Omi STT API — Data Processing Agreement

Version 2.0 — Effective date: 5 August 2026

This Data Processing Agreement ("DPA") forms part of the Omi STT API service

terms (the "Agreement") between Omi Health B.V., KVK 69497680, Eindhoven,

the Netherlands ("Omi") and the customer accepting the Agreement

("Customer"). It is built on the standard contractual clauses annexed to

Commission Implementing Decision (EU) 2021/915 and applies whenever Omi

processes personal data on Customer's behalf within the scope of Article 28

GDPR. It is concluded in electronic form in accordance with Article 28(9)

GDPR.

Section I — General

Clause 1 — Purpose and scope

(a) The purpose of this DPA is to ensure compliance with Article 28(3) and

(4) of Regulation (EU) 2016/679 (GDPR).

(b) Customer acts as controller and Omi acts as processor of the Customer

Personal Data described in Annex I.B. Where Customer itself acts as a

processor for a third-party controller, Customer is Omi's instructing party,

Omi is engaged as a sub-processor, and references to "controller" in this DPA

are read as references to Customer acting on the documented instructions and

with the authorisation of its controller. Customer warrants that its

instructions to Omi are authorised by that controller and that its own

contract with that controller permits Omi's engagement on these terms.

(c) This DPA applies to the processing of Customer Personal Data as specified

in Annex I.

(d) Annexes I to III are an integral part of this DPA.

(e) This DPA is without prejudice to obligations to which Customer is subject

under the GDPR.

(f) "Customer Personal Data" means personal data in Customer Content

processed by Omi on Customer's behalf. "Customer Content" means Job Content

(submitted audio, job-scoped custom vocabulary and job options, and the

transcripts and results generated from them) and persistent custom vocabulary

saved to Customer's account. Account, usage, and billing data that Omi

processes for its own purposes ("Service Data") is processed by Omi as an

independent controller under its Privacy Notice and is outside this DPA.

*Clause numbering follows the 2021/915 model clauses. The model's Clause 2

(invariability) and optional Clause 5 (docking) apply to the executed

standard clauses themselves and are not reproduced here.*

Clause 4 — Hierarchy

In the event of a contradiction between this DPA and the provisions of the

Agreement or any other agreement between the parties, this DPA prevails for

the processing of Customer Personal Data. Where the parties have separately

executed the standard contractual clauses of Commission Implementing Decision

(EU) 2021/915, those clauses prevail over this DPA.

Clause 3 — Interpretation

Terms defined in the GDPR have the same meaning in this DPA. This DPA shall

be read and interpreted in the light of the GDPR and shall not be interpreted

in a way that runs counter to rights and obligations provided for in the

GDPR or that prejudices the fundamental rights or freedoms of the data

subjects.

Section II — Obligations of the parties

Clause 6 — Description of processing

The details of the processing, in particular the categories of personal data

and the purposes for which it is processed on Customer's behalf, are

specified in Annex I. The rights and obligations of Customer as controller

are set out in this DPA, in particular in Clauses 7.1, 7.6, 7.7, 8, 9, and

10.

Clause 7 — Obligations of the parties

#### 7.1 Instructions

(a) Omi shall process Customer Personal Data only on documented instructions

from Customer, unless required to do so by Union or Member State law to which

Omi is subject; in that case, Omi shall inform Customer of that legal

requirement before processing, unless the law prohibits this on important

grounds of public interest. The Agreement, this DPA, each API request

(including the retention period selected for a job), and configuration made

through the console are Customer's documented instructions. Instructions

include any authorisation of international transfers under Clause 7.8.

Subsequent instructions may be given throughout the processing and shall be

documented.

(b) Omi shall immediately inform Customer if, in Omi's opinion, an

instruction given by Customer infringes the GDPR or other Union or Member

State data protection provisions.

#### 7.2 Purpose limitation

Omi shall process Customer Personal Data only for the purposes set out in

Annex I, unless it receives further documented instructions from Customer.

Omi does not use Customer Content to train, fine-tune, or evaluate any

model; does not sell it; does not use it for marketing; and does not derive

anything from it beyond the requested transcript and results.

#### 7.3 Duration of processing and deletion

(a) Processing takes place for the duration specified in Annex I.

(b) Submitted audio is deleted automatically upon completion or terminal

failure of processing. Transcripts from synchronous requests are not stored.

Results of asynchronous requests are stored solely for retrieval and deleted

automatically at the end of the retention period selected by Customer (1 to

72 hours; default 24 hours). Job-scoped custom vocabulary is deleted with

the job. Content is never written to operational logs or backups. The

retention period selected by Customer is Customer's documented instruction.

Retention particulars, including the effective minimum retention for jobs

configured with webhook delivery, are stated in the Service documentation

and Annex I.

(c) Persistent custom vocabulary saved to Customer's account outside an

individual job is account configuration, not Job Content. Its content,

storage, and deletion behaviour are described in Annex I. Customer may

delete it through the Service at any time, and Omi deletes it on account

termination.

#### 7.4 Security of processing

(a) Omi shall implement at least the technical and organisational measures

specified in Annex II to ensure the security of Customer Personal Data,

including protection against a breach of security leading to accidental or

unlawful destruction, loss, alteration, unauthorised disclosure, or access

(personal data breach). In assessing the appropriate level of security, the

parties take due account of the state of the art, the costs of

implementation, the nature, scope, context, and purposes of processing, and

the risks involved for data subjects.

(b) Omi grants its personnel access to Customer Personal Data only to the

extent strictly necessary for implementing, managing, and monitoring the

Agreement. Omi ensures that persons authorised to process Customer Personal

Data have committed themselves to confidentiality or are under an

appropriate statutory obligation of confidentiality.

#### 7.5 Sensitive data

The Service is designed to process audio that contains data concerning

health and other special categories of personal data (Article 9 GDPR). Omi

applies the specific restrictions and additional safeguards identified in

Annex II for such data, including strict purpose limitation, the deletion

scheme in Clause 7.3, encryption in transit and at rest, role-based access

restriction with logging, and audit logs designed to contain no Customer

Content.

#### 7.6 Documentation, compliance, and audits

(a) The parties shall be able to demonstrate compliance with this DPA. Omi

shall deal promptly and adequately with inquiries from Customer about the

processing of Customer Personal Data.

(b) Omi shall make available to Customer all information necessary to

demonstrate compliance with the obligations in this DPA and stemming

directly from the GDPR, including this DPA, the current sub-processor list,

Annex II, deletion (purge-probe) evidence, and third-party audit reports or

certifications when available.

(c) At Customer's request, Omi shall permit and contribute to audits of the

processing activities covered by this DPA, at reasonable intervals or if

there are indications of non-compliance. Customer may conduct the audit

itself or mandate an independent auditor; audits may include inspections at

Omi's premises or physical facilities and shall, where appropriate, be

carried out with reasonable notice. Absent indications of non-compliance,

audits occur no more than once per twelve months, on at least thirty (30)

days' notice, during business hours, without unreasonable disruption, under

confidentiality, and at Customer's cost. These limits do not apply where an

audit is prompted by a personal data breach affecting Customer Personal

Data, a request or investigation by a competent supervisory authority,

credible indications of material non-compliance, or a binding legal deadline

of Customer; in those cases Omi contributes without the frequency and

notice limits, and Omi bears the costs where material non-compliance is

found.

(d) The parties shall make the information referred to in this Clause,

including the results of any audits, available to the competent supervisory

authority or authorities on request.

#### 7.7 Use of sub-processors

(a) Customer grants Omi general written authorisation to engage

sub-processors from the agreed list in Annex III. Omi shall specifically

inform Customer in writing of any intended change of that list through the

addition or replacement of sub-processors at least thirty (30) days in

advance, giving Customer sufficient time to object before the engagement.

Omi shall provide the information necessary to enable Customer to exercise

its right to object.

(b) If Customer objects on reasonable data-protection grounds, the parties

shall discuss the objection in good faith and Omi shall, where reasonably

possible, offer an alternative that avoids the objected-to sub-processor. If

no reasonable alternative exists, Customer may terminate the affected

Service, retrieving its results first in accordance with Clause 10(d).

(c) Where Omi engages a sub-processor to carry out specific processing

activities on behalf of Customer, it shall do so by way of a contract that

imposes on the sub-processor, in substance, the same data protection

obligations as those imposed on Omi under this DPA. Omi shall ensure that

the sub-processor complies with the obligations to which Omi is subject

under this DPA and the GDPR.

(d) At Customer's request, Omi shall provide a copy of such a sub-processor

agreement and subsequent amendments, redacted to the extent necessary to

protect business secrets or other confidential information, including

personal data.

(e) Omi remains fully responsible to Customer for the performance of each

sub-processor's obligations under its contract with Omi, and shall notify

Customer of any failure by a sub-processor to fulfil its contractual

obligations.

(f) Omi shall agree a third-party beneficiary clause with each sub-processor

whereby, in the event Omi has factually disappeared, ceased to exist in law,

or become insolvent, Customer has the right to terminate the sub-processor

contract and to instruct the sub-processor to erase or return the personal

data.

#### 7.8 International transfers

(a) Any transfer of Customer Personal Data to a third country or an

international organisation by Omi shall take place only on the basis of

documented instructions from Customer or to fulfil a specific requirement

under Union or Member State law to which Omi is subject, and shall comply

with Chapter V GDPR.

(b) Steady-state processing of Customer Content takes place in the EU (AWS

eu-central-1, Frankfurt). During the disclosed preview transition period,

processing may also occur in AWS us-east-1 (United States). Customer agrees

that, where processing by a sub-processor involves a transfer within the

meaning of Chapter V GDPR, Omi and the sub-processor ensure compliance with

Chapter V by means of the applicable module of the standard contractual

clauses adopted under Article 46(2)(c) GDPR as incorporated in that

sub-processor's data processing agreement with Omi — for AWS, the AWS GDPR

Data Processing Addendum, which incorporates the SCC modules applicable to

the parties' roles — provided the conditions for the use of those clauses

are met. Omi documents the transfer assessments for such transfers and

makes them available under Clause 7.6.

(c) This Clause remains in effect after the preview transition ends. It

governs any non-EEA processing that may arise, including support, remote

access, or disaster recovery, for as long as this DPA is in force.

Clause 8 — Assistance to Customer

(a) Omi shall promptly notify Customer of any request it receives from a

data subject relating to Customer Personal Data. Omi shall not respond to

the request itself, unless authorised to do so by Customer.

(b) Omi shall assist Customer in fulfilling its obligations to respond to

data subjects' requests to exercise their rights, taking into account the

nature of the processing. Where Customer Content has already been deleted

under Clause 7.3, Omi's assistance consists of promptly confirming that

fact; nothing in this DPA requires Omi to recreate deleted data.

(c) Omi shall furthermore assist Customer in ensuring compliance with the

following obligations, taking into account the nature of the processing and

the information available to Omi:

1. the obligation to carry out a data protection impact assessment where a

type of processing is likely to result in a high risk to the rights and

freedoms of natural persons (Article 35 GDPR);

2. the obligation to consult the competent supervisory authority prior to

processing where a data protection impact assessment indicates a high

residual risk (Article 36 GDPR);

3. the obligation to ensure that personal data is accurate and up to date,

by informing Customer without delay if Omi becomes aware that personal

data it is processing is inaccurate or has become outdated;

4. the obligations in Articles 32 to 34 GDPR.

(d) The measures by which Omi provides this assistance, and its scope and

extent, are set out in Annex II.

Clause 9 — Notification of personal data breach

In the event of a personal data breach, Omi shall cooperate with and assist

Customer so that Customer can comply with its obligations under Articles 33

and 34 GDPR, taking into account the nature of the processing and the

information available to Omi.

(a) In the event of a personal data breach concerning Customer Personal

Data processed by Omi, Omi shall notify Customer without undue delay and in

any event within 48 hours after having become aware of the breach. The

notification shall contain, at least: (1) a description of the nature of

the breach, including where possible the categories and approximate number

of data subjects and data records concerned; (2) the details of a contact

point where more information can be obtained; and (3) the likely

consequences of the breach and the measures taken or proposed to address

it, including, where appropriate, measures to mitigate its possible adverse

effects.

(b) Where, and insofar as, it is not possible to provide all of this

information at the same time, the initial notification shall contain the

information then available, and further information shall be provided

subsequently without undue delay as it becomes available.

(c) Omi shall assist Customer in notifying the breach to the competent

supervisory authority and, where required, in communicating it to affected

data subjects, and in obtaining the information that Article 33(3) GDPR

requires the controller's notification to state.

Section III — Final provisions

Clause 10 — Non-compliance, termination, and deletion or return

(a) Without prejudice to the GDPR, if Omi is in breach of its obligations

under this DPA, Customer may instruct Omi to suspend the processing of

Customer Personal Data until Omi complies with this DPA or the Agreement is

terminated. Omi shall promptly inform Customer if it is unable to comply

with this DPA, for whatever reason.

(b) Customer is entitled to terminate the Agreement insofar as it concerns

processing under this DPA where: (1) processing was suspended under point

(a) and compliance is not restored within a reasonable time and in any

event within one month of suspension; (2) Omi is in substantial or

persistent breach of this DPA or its GDPR obligations; or (3) Omi fails to

comply with a binding decision of a competent court or supervisory

authority regarding its obligations under this DPA or the GDPR.

(c) Omi is entitled to terminate the Agreement insofar as it concerns

processing under this DPA where, after informing Customer that an

instruction infringes applicable legal requirements under Clause 7.1(b),

Customer insists on compliance with that instruction.

(d) At the end of the provision of the Services, Omi shall, at Customer's

choice, delete all Customer Personal Data processed on Customer's behalf

and certify that it has done so, or return it and delete existing copies,

unless Union or Member State law requires storage. Retrieval of results

through the API before termination constitutes return of Job Content; any

remaining Customer Content is deleted by the standing mechanics of Clause

7.3, and persistent custom vocabulary is deleted on account termination.

Written confirmation of deletion is available on request. Until deletion or

return is complete, Omi continues to ensure compliance with this DPA.

Clause 11 — Governing law

This DPA is governed by the law of the Netherlands, as provided in the

Agreement, without prejudice to mandatory provisions of the GDPR.


Annex I — List of parties and description of processing

A. List of parties

Controller / instructing party (Customer): the legal entity accepting

the Agreement, as recorded at acceptance (legal name, registered address,

contact person, and, where designated, data protection officer). Where

Customer acts as processor for a third-party controller, Clause 1(b)

applies.

Processor: Omi Health B.V., KVK 69497680, Eindhoven, the Netherlands.

Privacy contact: as published at /legal (privacy contact address).

B. Description of processing

Subject matter and nature. Automated conversion of speech to text:

receipt of audio submitted through the API, transcription (including

optional speaker diarization, formatting, and application of custom

vocabulary), and delivery of transcripts and results. Transcription runs on

Omi-operated infrastructure; no third-party model APIs are in the inference

path.

Purpose. Solely to provide, secure, and support the Service for

Customer.

Categories of data subjects. Speakers in submitted audio, including

patients, healthcare professionals, and other individuals whose speech or

personal details are captured in a recording; individuals mentioned in

audio or vocabulary entries.

Categories of personal data.

them: identifiers, contact details, dates, and clinical narrative.

labels) derived from the audio.

(may contain names, drug names, diagnoses, and other patient-related

terms).

same kinds of terms).

settings, status).

Special categories of data. Data concerning health (Article 9 GDPR) is

expected in submitted audio, transcripts, and vocabulary; the Service is

designed for it. Safeguards: Clause 7.5 and Annex II.

Duration of processing.

completion or terminal failure of processing; synchronous transcripts not

stored; asynchronous results stored solely for retrieval and deleted at

the end of the Customer-selected retention period (1 to 72 hours; default

24 hours); job-scoped vocabulary deleted with the job. Jobs configured

with webhook delivery have an effective minimum retention of 9 hours to

cover webhook retry mechanics; the Service documentation states the

current values.

deletable by Customer in the console at any time; deleted on account

termination.

content-free result tombstones up to 96 hours.

Annex II — Technical and organisational measures

Concrete measures implemented by Omi for the EU production environment (AWS

account region eu-central-1, Frankfurt). Omi may update these measures

provided the level of protection is not reduced.

Encryption in transit. TLS for all external API, console, and webhook

traffic; internal service traffic within a private VPC.

Encryption at rest. Customer-managed AWS KMS keys (CMK) with automatic

rotation for all content-bearing stores: S3 (SSE-KMS with bucket keys),

DynamoDB tables, SQS queues, EBS volumes, and CloudWatch log groups. A

dedicated audit CMK protects audit storage.

Access control and least privilege. Role-based access control;

least-privilege IAM policies; no standing human access to Customer Content;

human access only for security or abuse investigation, logged.

Administrative access to hosts via AWS Systems Manager (no public SSH);

administrative command output is kept content-free.

Authentication and key management. Customer API keys are stored as

SHA-256 hashes only; the plaintext key is shown once at creation and cannot

be retrieved by Omi staff. Secrets are held in AWS Secrets Manager.

Customer identity for the console is managed in an Omi-operated Keycloak

instance (identity data only; no Customer Content).

Audit logging. Immutable, content-free audit trail: security and

compliance events are delivered to an S3 bucket with Object Lock in

COMPLIANCE mode (2,192-day retention); CloudTrail with log-file validation.

The audit schema is designed to contain no audio, transcript, filename, or

URL content. Regular automated log-redaction sweeps verify that operational

logs contain no Customer Content.

Tenant isolation. Per-customer API keys scope every request; jobs,

results, and vocabulary are partitioned per account; authorisation is

enforced on every retrieval.

Data minimisation and retention. The retention scheme of Clause 7.3:

automatic deletion of audio on completion or terminal failure; no storage

of synchronous transcripts; Customer-selected retention (1-72 hours,

default 24 hours) for asynchronous results, enforced by an application

reaper with a short independent storage-lifecycle backstop; job queues and

dead-letter queues capped at 72 hours; operational logs retained 3 days;

content-free usage metadata 90 days; no backup tier is configured for the

Customer Content store, and Customer Content is not written to operational

logs or backups. An automated hourly purge probe verifies deletion

end-to-end and produces exportable evidence.

EU processing. Customer Content is processed in eu-central-1

(Frankfurt) in steady state; any non-EEA processing is governed by Clause

7.8. Identity data for the console is hosted on Microsoft Azure (Sweden

Central); website static assets are served via CDN; neither path carries

Customer Content. The API hostname is DNS-only and API traffic does not

transit the website CDN.

Availability and resilience. Multi-AZ load balancing for the API;

encrypted managed database with automated backups (identity/account data

only, 7-day retention); infrastructure as code with drift monitoring;

queue-based retry semantics for asynchronous work.

Personnel. Confidentiality undertakings for all persons authorised to

process personal data; written workforce training and sanctions program.

Assistance measures (Clauses 8 and 9). Named privacy contact; breach

intake and escalation runbook with templates for Article 33(3) content;

console and API access for Customer self-service retrieval and deletion;

deletion confirmations on request; sub-processor list with change

notification.

Testing and evaluation. Scheduled purge-probe verification of the

deletion scheme; periodic log-redaction and temp/spool sweeps; conformance

runs with evidence packs stored in the immutable audit bucket.

Annex III — Sub-processors

Customer authorises the following sub-processors (Clause 7.7(a)). The live

list, with the change-notification mechanism (at least 30 days' advance

notice), is published at /legal/sub-processors.

1. Amazon Web Services EMEA SARL (Luxembourg) — cloud infrastructure

hosting and processing of Customer Content. Location: eu-central-1

(Frankfurt) primary; interim us-east-1 (United States) during the

disclosed preview transition, under the AWS GDPR Data Processing

Addendum, which incorporates the applicable SCC modules (Clause 7.8).

2. Microsoft Ireland Operations Ltd — Microsoft Azure (Sweden Central)

— hosting for the Omi-operated Keycloak identity service. Processes

customer-user account and identity data only (name, business email,

credential and authentication-event data). Never processes audio,

transcripts, or PHI.

3. Cloudflare, Inc. — website content delivery network and Turnstile

bot protection for the public website and console assets. The API

hostname is DNS-only: API traffic, including all Customer Content, does

not transit Cloudflare.

4. Stripe (Stripe Payments Europe, Ltd.) — billing and payment

processing for the Service. Processes billing contact and transaction

data; card data is collected directly by Stripe and never touches Omi

systems. Never processes Customer Content.