Effective Date: Aug 25, 2026
Data Processing Addendum
This Data Processing Addendum including all of its Annexes (this “Addendum”) supplements and forms part of the contract under which Ambient AI, Inc. (“Ambient”) has agreed to provide the applicable Service(s) to the Customer identified therein (“Customer”, and together with Ambient, the “Parties”). (the “Agreement”).
All capitalized terms used but not otherwise defined herein have the respective meanings ascribed to them in the Agreement.
Customer has purchased a subscription to the Software pursuant to the Agreement that involves the Processing of Personal Data subject to Data Protection Laws (the “Service”).
In the provision of the Service by Ambient to Customer pursuant to the Agreement, Customer acts as Controller and Ambient acts as Processor or Service Provider with respect to the Personal Data, or, as the case may be, Customer acts as a Processor for its end-user customers (including such end-user customers’ affiliated companies as ultimate Controllers) and Ambient will act as a sub-Processor acting on the instruction of the Customer vis-à-vis its end-user customers.
The Parties agree as follows:
Definitions
Unless otherwise defined in the Agreement, all capitalized terms used in this Addendum will have the meanings given to them herein or in applicable Data Protection Laws.
“Controller” means the entity or Business which solely or jointly with other entities determines the purposes and means of the Processing of Personal Data, and for the purposes of this Addendum means Customer, including when acting on behalf of its own end-user customer.
“Data Breach” has the meaning given to it in the Data Protection Laws and for the purpose of this Addendum relates to the Personal Data Processed by Ambient on behalf of Customer.
“Data Protection Laws” means, to the extent applicable to Customer’s use of the Software, all applicable data protection and privacy laws, their implementing regulations, regulatory guidance, and secondary legislation, each as updated or replaced from time to time, including, as they may apply: (i) the General Data Protection Regulation ((EU) 2016/679) (“GDPR”) and any applicable national implementing laws; (ii) the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018; (iii) U.S. legislation (e.g., the California Consumer Privacy Act and the California Privacy Rights Act); and (iv) any other laws that may be applicable.
“Data Subject” means the identified or identifiable person to whom the Personal Data relates, as defined in applicable Data Protection Laws.
“EEA” means the European Economic Area.
“EU Standard Contractual Clauses” (or “EU SCCs” or “Clauses”) means the standard data protection clauses for the transfer of Personal Data to processors established in third countries, as described in Article 46 of the GDPR pursuant to the European Commission’s decision (C(2010)593) of 5 February 2010 on Standard Contractual Clauses, as approved by the European Commission in Implementing Decision 2021/914/EU of 4 June 2021, as each may be amended, updated, or replaced from time to time.
“Personal Data” has the meaning given to it in the Data Protection Laws and, for the purpose of this Addendum, relates to the Personal Data Processed by Ambient on behalf of Customer as described in Section 3.
“Processing” has the meaning given to it in the Data Protection Laws and “process,” “processes” and “processed” will be construed accordingly.
“Processor” means the entity or Service Provider which Processes Personal Data on behalf of the Controller, as defined in applicable Data Protection Laws, and for the purposes of this Addendum means Ambient.
Compliance with Laws
Each Party will comply with the Data Protection Laws as applicable to it. In particular, Customer will comply with its obligations as Controller (or on behalf of Controller), and Ambient will comply with its obligations as Processor.
Data Processing
- Roles of the Parties. The Parties acknowledge and agree that, with regard to the Processing of Personal Data where such terms are used by applicable Data Protection Laws, (i) Customer is the Controller; Ambient is the Processor or Service Provider; and the Processor may engage sub-Processors or other Service Providers pursuant to Section 10 of this Addendum.
- Customer Obligations.
- Customer (as Controller or on behalf of the ultimate Controller) undertakes that all instructions for the Processing of Personal Data under the Agreement, this Addendum, or as otherwise agreed will comply with the Data Protection Laws, and such instructions will not in any way cause Ambient to be in breach of any Data Protection Laws.
- The Customer will have sole responsibility for the means by which the Customer acquired the Personal Data.
- Ambient’s Processing of Personal Data
- Ambient will Process Personal Data only in accordance with Customer’s (i) instructions as outlined in the Agreement and this Addendum or (ii) as otherwise documented by Customer, in either event only as permitted by applicable Data Protection Laws and for the purpose of providing the Products to Customer in accordance with the terms of the Agreement.
- Unless prohibited by applicable law, Ambient will notify Customer if, in its opinion, an instruction infringes any Data Protection Law to which it is subject, in which case Ambient will be entitled to suspend performance of such instruction without any liability to Customer until Customer confirms in writing that such instruction is valid under such Data Protection Law. Any additional instructions regarding the manner in which Ambient Processes the Personal Data will require prior written agreement between Ambient and Customer.
- Ambient will not be liable in the event of any claim brought by a third party, including, without limitation, a Data Subject, arising from any act or omission of the Processor to the extent that such act or omission is a result of the Customer’s instructions.
- Ambient will not disclose Personal Data to any government, except as necessary to comply with applicable law or a valid and binding order of a law-enforcement agency (such as a subpoena or court order). If Ambient receives such an order, Ambient will notify Customer of the request it has received so long as Ambient is not legally prohibited from doing so.
- Where Ambient acts as Customer’s Service Provider, Ambient shall not: (i) sell Personal Data; (ii) collect, retain, use, or disclose Personal Data (a) for any purpose other than providing the Products specified in the Agreement and this Addendum, or (b) outside of the direct business relationship between Ambient and Customer; or (iii) combine this Personal Data with Personal Data that Processor obtains from other sources except as permitted by applicable Data Protection Laws. Ambient certifies that it understands the prohibitions outlined in this Section 3(c)(v) and will comply with them.
- Ambient will take reasonable steps to ensure that individuals with access to or involved in the Processing of Personal Data are subject to appropriate confidentiality obligations and/or are bound by related obligations under Data Protection Laws or other applicable laws.
- The duration of the Processing, the nature and specific purposes of the Processing, the types of Personal Data Processed, and categories of Data Subjects under this Addendum are further specified in the Annexes to this Addendum and, on a more general level, in the Agreement.
International Transfers.
At all times during the term of the Agreement, Customer (as data exporter) and Ambient (as data importer) shall comply with the Standard Contractual Clauses with respect to Personal Data relating to European Economic Area (EEA), Swiss, and/or United Kingdom (UK) Data Subjects Transfers of Personal Data Outside the EEA.
Technical and Organizational Measures
Ambient will implement appropriate technical and organizational measures to ensure a level of security of Personal Data appropriate to the risk, as further described in Annex II. In assessing the appropriate level of security, Ambient will take into account the risks presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed.
Data Subject Rights
Ambient will assist Customer in responding to Data Subjects’ requests to exercise their rights under Data Protection Laws. To that effect, Ambient will (i) to the extent permitted by applicable law, promptly notify Customer of any request received directly from Data Subjects to access, correct or delete its Personal Data without responding to that request, and (ii) upon written request from Customer, provide Customer with information that Ambient has available to reasonably assist Customer in fulfilling its obligations to respond to Data Subjects exercising their rights under the Data Protection Laws.
Data Protection Impact Assessments
If Customer is required under Data Protection Laws to conduct a Data Protection Impact Assessment, Ambient will, upon written request, use commercially reasonable efforts to assist, to the extent Customer does not otherwise have access to the relevant information, including reasonable assistance with any cooperation or prior consultation with supervisory authorities.
Audit of Technical and Organizational Measures
Upon written request (no more than once annually) and at Customer’s sole cost, Customer may verify Ambient’s compliance with its data protection obligations as specified in this Addendum by: (i) submitting a security-assessment questionnaire; and (ii) if Customer is not satisfied with the responses to the questionnaire, conducting an audit meeting with Ambient’s information security experts on a mutually agreeable time. Such interviews will be conducted with a minimum of disruption to Ambient’s normal business operations and subject always to Ambient’s agreement on scope and timings. Such audit will be performed during normal business hours, in such a manner as not to unreasonably disrupt normal business operations, and in no event will take place over the course of more than two business days. The Customer may perform the verification described above by itself or through a mutually agreed upon third party auditor, so long as Customer or its authorized auditor executes a mutually agreed upon non-disclosure agreement. Customer will be responsible for any actions taken by its authorized auditor. All information disclosed by Ambient under this Section 8 will be deemed Ambient’s Confidential Information, and Customer will not disclose any audit report to any third party except as obligated by law, court order or administrative order by a government agency. Ambient will remediate any mutually agreed, material deficiencies in its technical and organizational measures identified by the audit procedures described in this Section 8 within a mutually agreeable timeframe.
Breach Notification
If Ambient becomes aware of a Data Breach, Ambient will notify Customer without undue delay, and in any case, within seventy-two (72) hours, cooperate, and take commercially reasonable steps to investigate, mitigate, and remediate. Ambient will provide all support necessary to enable Customer to comply with its legal obligations.
Sub-Processing
Ambient will delete or return Personal Data (at Customer’s option) within a reasonable period following termination or expiration of the Agreement, unless otherwise required by law.
Return or Deletion of Personal Data
- General Authorization. Customer authorizes Ambient to engage Ambient affiliates or third-party providers as Sub-processors. Ambient will impose contractual obligations on Sub-processors no less protective than this Addendum.
- Sub-processor List & Objection Right. Ambient maintains an updated list of Sub-processors (available upon written request) and may amend the list at any time with thirty (30) days advance written notice, including details of the Processing to be undertaken by the proposed Sub-processors. Customer may object in writing; Ambient will work in good faith to resolve objections. Ambient may choose to: (i) not use the Sub-processor to Process Personal Data for Customer or (ii) take corrective steps requested by Customer in its objection and use the Sub-processor once Customer deems such corrective steps were taken. If neither of these options are reasonably possible and Customer continues to object, Customer may terminate the affected portion of the Service with notice.
Termination
This Addendum shall automatically terminate upon the termination or expiration of the Agreement. Sections 1, 3(b), 3(c)(iii), 11, 13, and 14 of this Addendum shall survive the termination or expiration of this Addendum for any reason. This Addendum cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this Addendum shall automatically terminate.
Governing Law & Jurisdiction
This Addendum shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws. The Parties agree that Module Two shall apply. For the purposes of Clause 13 of the GDPR, the Supervisory Authority shall be the data exporter’s applicable Supervisory Authority. Data exporter shall notify data importer of the applicable Supervisory Authority by email at legal@ambient.ai and shall provide any necessary updates without undue delay. For the purposes of Clauses 17 and 18 of the EU SCCs, where applicable, to the extent that the governing law and jurisdiction provisions in the Agreement do not meet the requirements of the EU SCCs, the parties select Option 2 of Clause 17, and agree that the EU SCCs shall be governed by the law of the EU Member State in which the data exporter is established; where such law does not allow for third-party beneficiary rights, the EU SCCs shall be governed by the laws of the country of Ireland. Pursuant to Clause 18, any dispute between the Parties arising from the EU SCCs shall be resolved by the courts of Ireland, and the Parties submit themselves to such jurisdiction.
Entire Agreement; Conflict
Except as amended by this Addendum, the Agreement remains in full force and effect. In case of conflict on the subject matter herein, the terms of this Addendum shall control.
ANNEX I
List of Parties
Data exporter(s):
Name: The Customer named in the Agreement
Address: The address of the Customer’s corporate headquarters
Contact person’s name, position and contact details: The primary administrative contact listed in the Hosted Software
Activities relevant to the data transferred under these Clauses: Purchase of subscription and use of Software under the Agreement
Role (controller/processor): Controller
Data importer(s):
Name: Ambient AI, Inc.
Address: 555 Twin Dolphin Drive, Suite 610, Redwood City, CA 94065
Contact details: Vikesh Khanna, CTO, support@ambient.ai
Activities relevant to the data transferred under these Clauses: Processing of personal data to provide Products as set forth in the Agreement
Role (controller/processor): Processor
Description of Transfer
Categories of data subjects whose personal data is transferred
Customer’s physical security team members, any individuals whose faces are incidentally captured by Customer’s video cameras.
Categories of personal data transferred
- First name, last name, email address, and optionally, phone numbers of Customer’s physical security team members who are onboarded onto the Ambient platform, and any individuals whose faces are incidentally captured by Customer’s video cameras.
- If Customer has enabled badge integration with the Ambient Service, all badge system information provided by Customer containing Personal Data will be transferred. This may include employee/contractor name, timestamp, employee/contractor photo, access events, and other Personal Data Customer elects to share with the Ambient Service.
- Any other Customer Data containing Personal Data provided to Ambient for Processing via the Ambient Service, by or at the direction of Customer or Customer’s users.
Special categories or sensitive Personal Data transferred
None
The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis)
Ambient pulls in live video from security cameras and access events from access control systems on a continuous basis.
Nature of the processing
Ambient pulls in live video from security cameras to assist physical security teams in identifying security events of interest proactively. Ambient applies state of the art computer vision and AI to identify security of events and once identified these events are surfaced to physical security team members.
Purpose(s) of the data transfer and further processing
Ambient is used by physical security teams and assists physical security teams in identifying security events of interest proactively.
The period for which the personal data will be retained, or, if that is not possible, the criteria
During the Term of the Agreement and as provided therein.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:
Processing during the Term solely for providing the services/Products.
Competent Supervisory Authority
- maintain reasonable controls to ensure that only individuals who have a legitimate need to access Personal Data under the Agreement will have such access;
- promptly terminate an individual’s access to Personal Data when such access is no longer required for performance under the Agreement;
- log the appropriate details of access to Personal Data on Third Party’s systems and equipment, and retain such records for no less than 90 days; and
- be responsible for any unauthorized access to Personal Data under its custody or control or its Sub-processors custody or control.
ANNEX II
The Supervisory Authority applicable to the Data Exporter as notified to the Data Importer in accordance with Section 13 of the Addendum.
Technical and Organizational Measures
- In assessing the appropriate level of security, Data Importer will take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
- Data Importer will do the following:
- implement physical access controls designed to secure relevant facilities, infrastructure, data centers, hard copy files, servers, backup systems, and equipment (including mobile devices) used to access Personal Data, including controls to prevent, detect, and respond to attacks, intrusions, or other system failures;
- implement user authentication and access controls within operating systems, applications, equipment, and media;
- implement personnel security policies and practices restricting access to Personal Data, including background checks consistent with Applicable Law on all personnel who maintain, implement, or administer its information security program and safeguards;
- perform continuous monitoring of networks, systems, and devices (including services) to ensure the privacy, confidentiality, security, integrity, and availability of the Personal Data; and
- maintain a reasonable security monitoring and incident response program to both detect and effectively respond to security events across all systems affecting Personal Data.
Access Controls
To control access to Personal Data, Processor will:
- maintain reasonable controls to ensure that only individuals who have a legitimate need to access Personal Data under the Agreement will have such access;
- promptly terminate an individual’s access to Personal Data when such access is no longer required for performance under the Agreement;
- log the appropriate details of access to Personal Data on Third Party’s systems and equipment, and retain such records for no less than 90 days; and
- be responsible for any unauthorized access to Personal Data under its custody or control or its Sub-processors custody or control.