Data Processing Agreement

Effective Date: September 4, 2026

Last Updated: September 4, 2026

Document Version: 1.0

This Data Processing Agreement ("DPA") forms part of the agreement between Axespire Solutions Limited, a company incorporated in Jamaica ("Axespire", "YuhChat", "we", "us" or "our"), and the person or entity subscribing to or using the YuhChat Services ("Customer", "you" or "your").

This DPA governs Axespire's processing of Personal Data on behalf of the Customer in connection with the YuhChat Services, and is intended to establish the parties' respective responsibilities for the processing and protection of Personal Data and to support compliance with applicable data-protection law, including the Data Protection Act, 2020 of Jamaica, together with applicable regulations, codes, orders and guidance.

This DPA should be read together with the YuhChat Terms of Service and the YuhChat Privacy Policy.

CONTACT INFORMATION

Axespire Solutions Limited

Jamaica

Data Protection / Legal Contact: Admin@axespire.com

Website: YuhChat / Axespire Solutions

Data Protection Officer: Where required to be appointed under Applicable Data Protection Law, the relevant contact details will be made available to Customers through the applicable privacy or compliance documentation.

1. DEFINITIONS

1.1 "Applicable Data Protection Law" means all applicable laws, regulations, statutory instruments, regulatory requirements and binding guidance relating to the protection, privacy, security or processing of Personal Data applicable to either party in connection with the Services, including, where applicable, the Data Protection Act, 2020 of Jamaica, as amended or replaced from time to time.

1.2 "Axespire" means Axespire Solutions Limited, including its affiliates, employees, contractors and authorised personnel involved in providing the Services.

1.3 "Customer" means the individual, professional, business, organisation or other legal entity that subscribes to or uses YuhChat.

1.4 "Customer Data" means information submitted to, transmitted through, generated for, or otherwise processed by YuhChat on the Customer's behalf in connection with the Services. Customer Data may include Personal Data.

1.5 "Data Controller" has the meaning given to it under Applicable Data Protection Law and generally means the person or entity determining the purposes and manner in which Personal Data is processed.

1.6 "Data Processor" has the meaning given to it under Applicable Data Protection Law and generally means a person or entity processing Personal Data on behalf of a Data Controller.

1.7 "Data Subject" means an identifiable individual to whom Personal Data relates.

1.8 "End User" means an individual who communicates with a Customer through YuhChat, including a caller, prospective customer, patient, client, employee, supplier, visitor or other person interacting with the Customer.

1.9 "Personal Data" means personal data as defined by Applicable Data Protection Law, which may include names, telephone numbers, email addresses, recordings, transcripts, appointment information, communications, identifiers, location information, account information, IP addresses and other information capable of identifying an individual.

1.10 "Sensitive Personal Data" means Personal Data classified as sensitive under Applicable Data Protection Law. Under Jamaican law, this includes, among other categories, information relating to physical or mental health, genetic or biometric data, religious or philosophical beliefs, racial or ethnic origin, sex life, trade-union membership and certain criminal-offence information.

1.11 "Processing" includes obtaining, recording, storing, retrieving, consulting, using, transmitting, disclosing, combining, altering, deleting, destroying or otherwise handling Personal Data, whether manually or by automated means.

1.12 "Services" means YuhChat and related services provided by Axespire, including AI voice-assistant functionality, telephone communications, call routing, transcription, summaries, appointment scheduling, messaging, integrations, dashboards, analytics and related functionality.

1.13 "Subprocessor" means a third party engaged by Axespire to Process Personal Data on behalf of the Customer in connection with the Services.

2. ROLE OF THE PARTIES

2.1 Customer as Data Controller. Except where the parties expressly agree otherwise in writing, the Customer acts as the Data Controller of Customer Data processed through the Services, determining the purposes, categories of individuals, information collected, lawful basis, recording decisions, retention, and what automated actions YuhChat is authorised to perform.

2.2 Axespire as Data Processor. Axespire acts as the Data Processor for Customer Data to the extent that Axespire processes such data on behalf of the Customer, and shall process Customer Data only: to provide the Services; to maintain and secure the Services; to perform the Customer's documented instructions; as necessary to prevent fraud, abuse, security incidents or unlawful use; as required by Applicable Data Protection Law; or as otherwise expressly authorised by the Customer and permitted by law.

2.3 No Change of Roles by Contract Label. The parties acknowledge that their actual roles depend on the nature of the processing activities. Nothing in this DPA overrides the legal definitions or obligations imposed by Applicable Data Protection Law.

3. SUBJECT MATTER AND DURATION OF PROCESSING

3.1 Subject Matter. The subject matter of processing under this DPA is the provision and operation of the YuhChat Services, including receiving/making calls, routing, recording, transcribing, summarising, extracting information, scheduling, messaging, storing account/caller information, transferring calls to humans, integrations, support, abuse detection, and reliability maintenance.

3.2 Duration. Processing continues for the duration of the Customer's use of the Services and any additional period reasonably necessary to comply with legal obligations, resolve disputes, enforce agreements, maintain security records, complete deletion processes, or satisfy legitimate backup and disaster-recovery procedures.

4. CATEGORIES OF PERSONAL DATA

Depending on Customer's configuration, Customer Data may include: name; telephone number; email address; postal/business address; appointment information; customer/client identifiers; account information; communications and messages; call recordings; voice data; call transcripts; AI-generated summaries; notes; conversation content; scheduling information; technical information; device/network information; IP addresses; call metadata; contact preferences; and other information submitted by or on behalf of Customer.

The Customer is responsible for configuring the Services so that only information reasonably necessary for its intended purposes is collected.

5. CATEGORIES OF DATA SUBJECTS

Depending on Customer's use of YuhChat, Data Subjects may include: customers; prospective customers; patients; clients; employees; contractors; suppliers; business partners; visitors; callers; members of the public; professional contacts; authorised representatives; and other individuals communicating with the Customer.

6. CUSTOMER INSTRUCTIONS

6.1 The Customer instructs Axespire to process Personal Data as reasonably necessary to provide the Services and in accordance with this DPA, the Terms of Service, Customer's configuration, and written instructions issued through authorised accounts.

6.2 Unlawful Instructions. Axespire shall not knowingly be required to process Personal Data in a manner that violates Applicable Data Protection Law. If Axespire reasonably believes an instruction violates such law, it may suspend the affected processing while seeking clarification from Customer.

6.3 Customer may modify processing instructions through available YuhChat controls or written instructions; material technical changes may require separate agreement on implementation and fees.

7. CUSTOMER RESPONSIBILITIES

The Customer is responsible for: determining purposes and lawful basis for processing; providing appropriate privacy notices to Data Subjects; obtaining required consents; complying with recording/transcription requirements; ensuring End Users are informed of AI interaction where required; determining whether Sensitive Personal Data should be collected; configuring YuhChat appropriately; ensuring personnel access is authorised; responding to Data Subject requests where Customer is the Controller; maintaining accurate Customer-controlled data; determining retention periods; ensuring lawful use of integrations; ensuring outbound-calling compliance; conducting required DPIAs; complying with sector-specific requirements; and ensuring instructions given to Axespire are lawful.

The Customer shall not use YuhChat as a substitute for its own legal, regulatory, clinical, professional or compliance obligations.

8. AXESPIRE PROCESSING OBLIGATIONS

Axespire shall: (8.1) process only on documented instructions except where required by law; (8.2) ensure authorised personnel are subject to confidentiality obligations; (8.3) implement reasonable technical/organisational security measures; (8.4) provide reasonable assistance with access, rectification, deletion, restriction/objection requests, security incidents, DPIAs, and regulatory enquiries; (8.5) maintain reasonable records and controls to demonstrate compliance.

9. DATA SUBJECT RIGHTS

The Customer, as Data Controller, is primarily responsible for responding to Data Subject requests. Where Axespire receives such a request: it will not ordinarily respond substantively on Customer's behalf; may direct the Data Subject to Customer; will provide reasonable assistance where technically/commercially reasonable; and may disclose information where required by law.

The Jamaican Data Protection Act provides Data Subjects with rights relating to access, rectification, and automated decision-taking.

10. SECURITY MEASURES

Axespire shall maintain appropriate technical and organisational safeguards appropriate to the nature and risk of processing, which may include: access controls; authentication; role-based access; encryption in transit; encryption or equivalent protections for stored information where appropriate; logging and monitoring; vulnerability management; network security; secure infrastructure configuration; backups and disaster recovery; incident-response procedures; credential management; least-privilege access; personnel confidentiality requirements; and periodic review of controls.

10.1 No internet-connected system can be guaranteed completely secure; Axespire does not guarantee that unauthorised access or security incidents will never occur.

11. PERSONAL DATA BREACHES

11.1 If Axespire becomes aware of a security incident involving Customer Personal Data that constitutes or may reasonably constitute a breach, it shall notify Customer without undue delay, including (where reasonably practicable) the nature of the incident, affected systems, categories of data involved, approximate number of affected Data Subjects, likely consequences, mitigation measures, and a contact point.

11.2 Axespire shall take reasonable steps to investigate and mitigate the incident.

11.3 Customer remains responsible for determining whether it must notify the Information Commissioner, Data Subjects, or another authority; Axespire will reasonably assist with necessary information.

11.4 A notification under this section is not an admission of legal responsibility.

12. SUBPROCESSORS

12.1 Customer generally authorises Axespire to engage Subprocessors reasonably necessary to provide the Services (see Annex 3 for categories).

12.2 Axespire shall require Subprocessors processing Customer Personal Data to undertake appropriate contractual obligations concerning confidentiality, security and data protection.

12.3 Axespire remains responsible for the performance of its obligations under this DPA in relation to authorised Subprocessors, subject to the limitations in the Terms of Service and Applicable Law.

12.4 Axespire maintains a current Subprocessor List identifying material Subprocessors used to process Customer Personal Data (see companion document).

13. INTERNATIONAL DATA TRANSFERS

YuhChat may rely on service providers located outside Jamaica; accordingly Customer Personal Data may be processed, stored or transferred outside Jamaica where reasonably necessary to provide the Services.

Axespire shall implement reasonable contractual and organisational measures supporting compliance with Applicable Data Protection Law governing international transfers, including Jamaica's eighth data-protection standard concerning transfers outside Jamaica.

Where legally required, Axespire will take reasonable steps to identify the relevant destination or category of destination and applicable safeguards.

14. SENSITIVE PERSONAL DATA

14.1 The Customer is responsible for determining whether collection or processing of Sensitive Personal Data is legally permitted and whether additional safeguards are required.

14.2 Healthcare Use. Where YuhChat is used by a medical clinic or health-related organisation, Customer Data may include health information; Customer remains responsible for lawfulness, legal basis, patient notices, consent, professional confidentiality, retention, access controls, and sector-specific obligations.

14.3 Customer should configure YuhChat to minimise collection of Sensitive Personal Data where not necessary.

14.4 Where AI functionality processes Sensitive Personal Data, Customer must ensure such processing is legally authorised and consistent with its privacy notices and instructions.

15. CALL RECORDINGS AND VOICE DATA

Voice recordings and related information may constitute Personal Data and potentially biometric or other Sensitive Personal Data under Applicable Data Protection Law.

Customer is responsible for determining whether calls should be recorded; whether recording is legally permitted; notice/consent requirements; recording disclosures; purposes; retention; access; transcription; and deletion.

Axespire shall process recordings and transcripts according to Customer's configuration and instructions, subject to the Services' operation and Applicable Data Protection Law.

16. AI PROCESSING

16.1 YuhChat uses artificial intelligence and automated systems to process communications and generate responses, summaries, classifications, transcriptions and other outputs.

16.2 The Customer authorises Axespire to use AI systems and supporting technology to provide the Services.

16.3 No General-Purpose Training on Identifiable Customer Data. Unless expressly agreed in writing, Axespire will not intentionally use identifiable Customer Data to train a general-purpose AI model. This does not prevent operating the Services, fraud/security detection, debugging, performance monitoring, analytics, legal compliance, or use of aggregated/de-identified information.

16.4 Where third-party AI providers process Customer Personal Data, Axespire will treat them as Subprocessors where appropriate and require appropriate contractual protections.

16.5 AI systems may produce inaccurate, incomplete, misunderstood or inappropriate outputs; Customer remains responsible for reviewing and supervising AI-generated information where errors could materially affect an individual.

17. AUTOMATED DECISION-MAKING

Unless expressly agreed in writing, YuhChat is not intended to make legally binding or similarly significant automated decisions about Data Subjects. Customer remains responsible for determining whether its use involves regulated automated decision-making and whether human oversight is required.

18. MEDICAL, LEGAL AND OTHER PROFESSIONAL SERVICES

18.1 YuhChat is not itself a healthcare provider and is not intended to diagnose, prescribe treatment, determine medical emergencies, or replace qualified healthcare professionals; Customer remains responsible for clinical decisions.

18.2 YuhChat does not provide legal advice merely because used by a law firm; Customer remains responsible for legal advice, privilege, and professional obligations.

18.3 Customer remains responsible for determining whether YuhChat may lawfully be used for its intended regulated processing activities.

19. DATA MINIMISATION

Personal Data should be adequate, relevant and limited to what is necessary. Customer shall avoid instructing YuhChat to collect unnecessary Personal Data and should configure prompts, forms, workflows and integrations accordingly — reflecting Jamaica's data-minimisation standard.

20. DATA ACCURACY

Customer is responsible for the accuracy of Customer Data it supplies or controls. Because YuhChat may automatically transcribe or interpret voice communications, transcripts and summaries may contain errors; Customer should review information where accuracy matters — reflecting Jamaica's accuracy standard.

21. DATA RETENTION

21.1 Customer is responsible for determining appropriate retention periods, subject to applicable law and available retention controls.

21.2 Retention periods may vary by configuration, subscription level, technical architecture, backups, security, legal, and operational requirements.

21.3 Axespire may retain information where reasonably necessary to comply with law, establish/defend legal claims, investigate security incidents, prevent fraud, enforce rights, or maintain required business records.

21.4 Deleted Customer Data may remain temporarily within encrypted or otherwise protected backups until overwritten or securely deleted per Axespire's retention procedures.

22. RETURN AND DELETION OF DATA

Upon termination, Axespire shall, subject to Applicable Data Protection Law and the Terms of Service: make Customer Data available for export where supported; delete or anonymise Customer Personal Data within a reasonable period; cease active processing except where legally required; and retain information only where reasonably necessary for legal, security, fraud-prevention or backup purposes.

Immediate deletion from all technical systems may not always be possible due to backups, disaster-recovery systems, or legal retention obligations.

23. DATA PROTECTION IMPACT ASSESSMENTS

Customer is responsible for conducting any DPIA required by Applicable Data Protection Law. Axespire shall provide information concerning its processing activities, security measures and technical controls to assist where reasonably necessary, without providing legal or regulatory certification merely by supplying such information.

24. REGULATORY COOPERATION

Where legally required, Axespire shall reasonably cooperate with Customer in responding to a data-protection authority's investigation, enquiry or request concerning processing performed under this DPA. Customer remains responsible for its own regulatory communications unless Applicable Law requires Axespire to communicate directly.

25. AUDIT RIGHTS

25.1 Upon reasonable written request, Axespire shall make available information reasonably necessary to demonstrate compliance with this DPA.

25.2 Where legally required or reasonably necessary following a material security incident, Customer may request an audit of Axespire's relevant processing activities, conducted on reasonable notice, during normal business hours, avoiding unnecessary disruption, respecting confidentiality, and not requiring disclosure of trade secrets except where legally required.

25.3 Unless otherwise required by law, Customer bears its own audit costs; Axespire may charge reasonable pre-agreed costs for substantial assistance beyond ordinary compliance support.

26. CONFIDENTIALITY

Each party shall protect confidential information received from the other. Customer Personal Data shall be treated as confidential. Axespire shall restrict access to personnel and authorised Subprocessors who require it for legitimate Service purposes.

27. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS

If Axespire receives a legally binding request from a governmental or law-enforcement authority for Customer Personal Data, it may disclose the requested information where legally required, using reasonable efforts to notify Customer beforehand where legally permitted (not required where prohibited by law or where notice would interfere with a lawful investigation).

28. CUSTOMER SECURITY

Customer is responsible for maintaining the security of its YuhChat account, passwords, API keys, access credentials, administrator accounts, connected applications, integrations, authorised users, and devices used to access YuhChat, and shall promptly notify Axespire of suspected unauthorised access.

29. THIRD-PARTY INTEGRATIONS

When Customer enables an integration (calendars, CRM, messaging, telecommunications, cloud, payment, or other Customer-selected systems), Customer Data may be transmitted to the relevant third party. Customer is responsible for reviewing the privacy/security practices of any third-party service it connects to YuhChat.

30. DATA OWNERSHIP

As between Axespire and Customer: Customer retains rights in Customer Data; Axespire retains rights in the YuhChat platform, software, technology, models, systems, processes and intellectual property; neither party receives ownership of the other's IP merely because Personal Data is processed through the Services.

31. AGGREGATED AND DE-IDENTIFIED INFORMATION

Axespire may create and use aggregated, statistical or de-identified information (no longer reasonably identifying a Customer or Data Subject) for analytics, capacity planning, security, performance monitoring, product development, research, business reporting, and service improvement. Axespire shall not represent such information as identifiable Customer Data.

32. INTERNATIONAL SERVICE PROVIDERS AND INFRASTRUCTURE

YuhChat is a technology platform that may depend upon third-party infrastructure located in Jamaica or other jurisdictions, including telecommunications carriers, cloud infrastructure, AI providers, databases, messaging platforms and other technical providers. Relevant categories and material Subprocessors are identified in Axespire's Subprocessor List.

33. CONFLICT WITH OTHER AGREEMENTS

Regarding Processing of Personal Data specifically: (1) this DPA prevails over the Terms of Service to the extent of a direct conflict; (2) the Terms of Service govern matters unrelated to Personal Data processing; (3) the Privacy Policy governs information Axespire collects independently as a Data Controller; (4) a separate written data-processing agreement signed by both parties prevails over this DPA to the extent expressly stated.

34. CHANGES TO THIS DPA

Axespire may update this DPA to reflect changes to Applicable Data Protection Law, regulatory requirements, the Services, technical infrastructure, Subprocessors, or improvements to data-protection practices. Where a change materially reduces Customer's data-protection rights, Axespire will provide reasonable notice where required by law or contract.

35. TERM AND TERMINATION

This DPA becomes effective when Customer accepts the Terms of Service or otherwise begins using the Services, and remains effective for as long as Axespire processes Customer Personal Data on Customer's behalf. Termination of the Services results in termination of this DPA once Axespire no longer processes Customer Personal Data, except for provisions that by their nature must survive.

36. LIABILITY

Liability under this DPA is subject to the liability provisions in the YuhChat Terms of Service, except to the extent prohibited or modified by Applicable Data Protection Law. Nothing in this DPA excludes liability that cannot lawfully be excluded.

37. INDEMNIFICATION

Indemnification obligations relating to Personal Data processing are governed by the indemnification provisions of the Terms of Service unless otherwise agreed in writing. Nothing in this section prevents a party from seeking any remedy available under Applicable Data Protection Law.

38. GOVERNING LAW

This DPA is governed by the laws of Jamaica, subject to mandatory provisions of Applicable Data Protection Law. The courts of Jamaica have jurisdiction to the extent provided by the Terms of Service and Applicable Law.

39. ELECTRONIC ACCEPTANCE

Customer may accept this DPA electronically through the YuhChat website, dashboard, account-registration process, order process or other electronic means. Electronic acceptance constitutes agreement to this DPA.

40. SEVERABILITY

If any provision of this DPA is determined invalid or unenforceable, the remaining provisions remain in effect; the invalid provision will be interpreted or replaced to achieve its lawful commercial purpose to the extent necessary.

41. NO WAIVER

Failure to enforce any provision of this DPA does not constitute a waiver of that or any other provision.

42. ENTIRE DATA PROCESSING AGREEMENT

This DPA, together with the Terms of Service, applicable Privacy Policy and any other written data-processing agreement between the parties, constitutes the agreement between the parties concerning the processing of Customer Personal Data.

ANNEX 1 — PROCESSING DETAILS

A. Subject Matter: Provision of YuhChat AI Voice Assistant and related communication, automation, scheduling, transcription, messaging, analytics and support services.

B. Duration: For the duration of the Customer's subscription and any additional period permitted or required under this DPA, the Terms of Service or Applicable Data Protection Law.

C. Nature of Processing: Collection; recording; storage; organisation; retrieval; consultation; transcription; analysis; AI processing; summarisation; transmission; routing; appointment scheduling; messaging; integration; deletion; anonymisation; destruction.

D. Personal Data Categories: Names; telephone numbers; email addresses; addresses; appointment information; communication content; call recordings; transcripts; voice data; customer identifiers; account information; technical information; call metadata; notes; preferences; other information supplied by Customer or End User.

E. Sensitive Personal Data: Health information; biometric or voice-related information; religious beliefs; racial or ethnic information; information relating to criminal allegations or proceedings; and other categories recognised by Applicable Data Protection Law. Customer is responsible for determining whether such processing is necessary and lawful.

F. Data Subject Categories: Customers; prospective customers; patients; clients; employees; contractors; suppliers; business partners; callers; visitors; professional contacts; members of the public.

ANNEX 2 — MINIMUM SECURITY CONTROLS

  • Access Control: unique accounts; authentication; role-based permissions; least-privilege principles; access revocation.
  • Data Protection: encryption in transit where supported; appropriate encryption or equivalent protections at rest; secure credential storage; controlled access to production systems.
  • Infrastructure Security: network controls; server hardening; system monitoring; logging; vulnerability management; patch management.
  • Availability: backups where applicable; disaster recovery procedures; service monitoring; restoration procedures.
  • Incident Response: identification; containment; investigation; mitigation; Customer notification where required.
  • Personnel: confidentiality obligations; access restrictions; security awareness; role-based access to Personal Data.
  • Testing: periodic security reviews; monitoring; assessment of relevant controls; remediation of identified risks.

Security measures may evolve as technology, threats and the YuhChat architecture develop.

ANNEX 3 — SUBPROCESSOR CATEGORIES

CategoryPurpose
Telecommunications providersTelephone connectivity and calling
DID/telephone-number providersTelephone numbers and routing
SIP/VoIP providersVoice communication infrastructure
AI/LLM providersAI processing and response generation
Speech-to-text providersTranscription
Text-to-speech providersAI voice generation
Cloud/VPS providersHosting and infrastructure
Database providersData storage
Messaging providersWhatsApp/SMS or related messaging
Calendar providersAppointment scheduling
Automation providersWorkflow execution
Monitoring providersSecurity and service monitoring
Authentication providersAccount and identity management

A current list of material Subprocessors is maintained separately by Axespire — see the companion Subprocessor List document.

ANNEX 4 — CUSTOMER RESPONSIBILITY CHECKLIST

Before using YuhChat with Personal Data, the Customer should ensure that it has:

  • Identified the purposes of processing.
  • Identified an appropriate lawful basis.
  • Provided appropriate privacy information to Data Subjects.
  • Determined whether call recording is lawful.
  • Determined whether call-recording disclosure is required.
  • Determined whether consent is required.
  • Configured appropriate retention periods.
  • Limited collection to information reasonably necessary.
  • Implemented appropriate access controls.
  • Reviewed connected third-party integrations.
  • Considered whether Sensitive Personal Data will be processed.
  • Considered whether a Data Protection Impact Assessment is required.
  • Established a process for handling Data Subject requests.
  • Established a process for responding to security incidents.
  • Ensured outbound calling complies with applicable law.
  • Ensured employees and authorised users understand their responsibilities.

IMPORTANT LEGAL NOTICE

This DPA is a contractual drafting document prepared for Axespire Solutions Limited / YuhChat. It is designed to support legal review and implementation and is not a representation that the document constitutes legal advice or has been reviewed, approved or endorsed by a Jamaican attorney-at-law.

© 2026 Axespire Solutions Limited. All rights reserved.

Document Version: 1.0 | Effective Date: September 4, 2026 | Last Updated: September 4, 2026