Data Processing Agreement (DPA) — Active

Legal

Data Processing Agreement (DPA)

Last updated: July 13, 2026

This Agreement governs the processing of the personal data that the User enters into the Active system, and sets out the parties' obligations in accordance with Israel's privacy protection laws. The Agreement forms an integral part of the Terms of Use.

1. Introduction

This Data Processing Agreement is entered into between Active Flow Ltd. (the "Company" or the "Holder") and the customer using the System's services (the "Customer" or the "Controller"), and its purpose is to govern the manner in which the personal data that the Customer enters into the System in the course of receiving the Services is processed, in accordance with Israel's Protection of Privacy Law, 5741-1981 (including Amendment No. 13), the Protection of Privacy Regulations (Data Security), 5777-2017, and the other regulations thereunder (together, the "Privacy Protection Laws").

2. Definitions

3. Roles of the Parties

3.1. The Customer is the controller of the database (Data Controller) with respect to the Personal Data the Customer enters into the System, and determines the purposes and means of the processing.

3.2. The Company acts as the holder (Data Processor), processing the data on behalf of the Customer and solely in accordance with the Customer's instructions, as set out in this Agreement and in Appendix A.

3.3. Nothing in this Agreement grants the Company any rights of ownership of, or control over, the data the Customer enters into the System, and the data remains the property of the Customer at all times.

4. Scope and Purposes of the Processing

4.1. The Company shall process the Personal Data solely for the purpose of providing, operating, securing and supporting the Services, in accordance with the Customer's instructions as reflected in the settings of the Customer's account and in the Customer's use of the System, and for no other purpose.

4.2. Some of the Services include processing by means of artificial intelligence, such as call transcription, call analysis and generation of insights. This processing is performed solely for the purpose of providing the Service to the Customer, and its outputs are available to the Customer in the Customer's account.

4.3. The Company shall not use the Personal Data of the Customer's end customers for its own independent purposes, including marketing, and shall not sell or rent such data to third parties.

4.4. The categories of data, the Data Subjects and the permitted processing operations are detailed in Appendix A to this Agreement.

5. Representations and Undertakings

5.1. The Customer represents that the data the Customer enters into the System was collected lawfully, that a lawful basis exists for its processing — including notification of Data Subjects to the extent required (and in particular with respect to the recording and transcription of calls) — and that the Customer's instructions to the Company do not violate the Privacy Protection Laws.

5.2. The Company represents that it possesses the knowledge, experience and means required to provide the Services, and that it is not aware of any conflict of interest between itself and its obligations under this Agreement.

5.3. Each party shall comply with the obligations applicable to it under the Privacy Protection Laws with respect to its role in the processing of the data.

6. Sub-Processors

6.1. The Customer authorizes the Company to engage Sub-Processors for the purpose of providing the Services (such as cloud hosting, communications and telephony, artificial intelligence services, payment clearing and messaging), provided that the Company enters into a written agreement with them containing data security and confidentiality obligations no less protective than those set out in this Agreement and in the Data Security Regulations.

6.2. The Company shall remain liable to the Customer for the processing performed by the Sub-Processors on its behalf.

6.3. A list of the principal Sub-Processors will be provided to the Customer upon written request.

7. Data Security

7.1. The Company implements technological, physical and organizational security measures appropriate to the security level applicable to the database under the Data Security Regulations, including: encryption of data in transit and at rest, management of access permissions on a need-to-know basis, user authentication, access logging and monitoring controls, separation of environments, backups and recovery procedures.

7.2. The Company is certified under the international information security standard ISO 27001 and maintains an information security management system in accordance with it.

7.3. The Company binds its employees and authorized personnel by confidentiality undertakings, conducts periodic training on data security and privacy protection, and restricts access to the data solely to employees who require it for the performance of their duties.

7.4. The Company has appointed a person responsible for information security, who can be contacted using the contact details set out in Appendix A.

8. Confidentiality

The Company shall keep the Personal Data confidential, and shall not disclose it or transfer it to any third party except to the extent necessary to provide the Services through Sub-Processors as set out in Section 6, in accordance with the Customer's instructions, or where required by law. The duty of confidentiality shall continue to apply after termination of the engagement.

9. Security Incidents

9.1. The Company shall notify the Customer, without unreasonable delay after becoming aware of it, of a severe Security Incident concerning the Customer's Personal Data, and shall provide the Customer with the details known to it about the incident, including the type of data exposed, the scope of the incident and the measures taken.

9.2. The Company shall act without delay to mitigate the damage caused by the incident, to remedy the deficiencies that led to it and to prevent its recurrence, and shall cooperate with the Customer to the extent required for the Customer's compliance with the reporting obligations applicable to the Customer, including reporting to the Israeli Privacy Protection Authority.

9.3. The Company shall not publish or issue any public notice regarding a Security Incident concerning the Customer's data without prior coordination with the Customer, unless required by law.

10. Data Subject Rights and Requests from Authorities

10.1. The System enables the Customer to access, correct and delete data independently. To the extent that further assistance is required in order to respond to a Data Subject's request (access, correction or deletion), the Company shall assist the Customer reasonably and without delay.

10.2. If a Data Subject contacts the Company directly regarding data controlled by the Customer, the Company shall refer the request to the Customer, unless otherwise required by law.

10.3. If the Company is required by a competent authority to disclose the Customer's data, it shall notify the Customer prior to the disclosure, to the extent permitted by law.

11. Audit and Reporting

11.1. Upon the Customer's request, and no more than once a year, the Company shall provide the Customer with a confirmation or report regarding its compliance with its obligations under this Agreement and under the Data Security Regulations.

11.2. The Company conducts periodic audits of its information security program, including as part of its ISO 27001 certification, and shall provide the Customer with evidence of a valid certification upon request.

12. Termination of the Engagement and Data Deletion

12.1. The Company shall retain the Personal Data only for as long as required for the provision of the Services or under law.

12.2. Upon termination of the engagement, the Customer has a grace period of 30 days to export the Customer's data from the System, as detailed in the Cancellation Policy. At the end of this period, or upon the Customer's written request, the Company shall delete the Personal Data or return it to the Customer, except for copies that it is required to retain under law or for the purpose of defense against legal claims, which shall remain subject to the confidentiality and security obligations of this Agreement.

13. Transfer of Data Outside Israel

Transfer of Personal Data outside the borders of Israel shall be carried out only in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001, and subject to a written engagement with the receiving party ensuring an adequate level of protection for the data.

14. General

14.1. This Agreement is governed by the laws of the State of Israel, and exclusive jurisdiction is vested in the competent courts as set out in the Terms of Use.

14.2. In the event of any conflict between this Agreement and the Terms of Use with respect to the processing of personal data, the provisions of this Agreement shall prevail.

14.3. The Company may update this Agreement from time to time in accordance with changes in law or in the Services. Notice of a material change will be provided on the website or by email.

Appendix A — Processing Details

A.1. Categories of Data Subjects

A.2. Categories of Personal Data

A.3. Permitted Processing Operations

Collection, receipt, storage, organization, access, analysis (including transcription and analysis by means of artificial intelligence), transfer between components of the Service, retrieval, correction, backup and deletion — all solely for the purpose of providing the Services.

A.4. Security Level

The data is processed in accordance with the security level applicable to the database under the Data Security Regulations, and in accordance with the Company's information security management system certified under ISO 27001.

A.5. Privacy and Information Security Contact