# Annex A. Data Processing Agreement (Article 28 of Regulation (EU) 2016/679)

This is a courtesy translation. In case of discrepancy, the Italian version prevails (Article 14.6 of the Conditions).

**Version 1.0**
**Published on 21 September 2026, effective from 21 October 2026**
**SHA-256 hash of the text: [HASH SHA-256]**

| Item | Content |
| --- | --- |
| Title | Annex A, Data Processing Agreement |
| Version | 1.0 |
| Text of this Annex | https://evolus.ai/en/data-processing-agreement |
| Annexed to | General Conditions of Use for Evolus and Employee AI ("Conditions"), version 2.0, published at https://evolus.ai/en/terms-of-use |
| Method of acceptance | Online, at the same time as the Conditions, in the manner set out in Article 3 of the Conditions. No separate signature |
| Processor | CodeDesign S.r.l., Via Nino Pesce 38, 18018 Taggia (IM), VAT No. IT01739830089 |
| Controller | The Customer, as identified in the act of acceptance |
| Data protection contact point | privacy@codedesign.it |
| List of sub-processors | https://evolus.ai/en/subprocessors |
| Technical and organisational measures | Annex B, version 1.0, published at https://evolus.ai/en/security-measures |
| Privacy notice for the platform | https://evolus.ai/en/privacy-policy |
| Plans and reserved features | Price List published at https://evolus.ai/en/pricing |

---

## Recitals

**(a)** CodeDesign S.r.l. (hereinafter the "Provider" or "CodeDesign") provides the Customer with the Evolus platform and the connected services, on the terms laid down in the Conditions.

**(b)** The provision of the Service entails the processing, by the Provider, of personal data of which the Customer is the controller.

**(c)** This Annex A constitutes the agreement provided for by Article 28, paragraph 3, of Regulation (EU) 2016/679 (hereinafter the "GDPR") and governs the processing of personal data carried out by the Provider on behalf of the Customer.

**(d)** Pursuant to Article 28, paragraph 9, of the GDPR this Annex is concluded in electronic form. It is accepted by the Customer at the same time as the Conditions, in the manner and with the records provided for by Article 3 of the Conditions, and is identified by version code 1.0 and by the SHA-256 hash of the text set out at the head of the document. No further signature is required.

**(e)** This Annex forms an integral and substantial part of the Contract. For matters of personal data protection alone its provisions prevail over those of the Conditions in the event of conflict, by express derogation from the order of precedence in Article 14.5 of the Conditions.

---

## 1. Definitions and roles

**1.1 Definitions.** For the purposes of this Annex:

a) **"GDPR"**: Regulation (EU) 2016/679. **"Applicable Legislation"**: the GDPR, Legislative Decree No. 196 of 30 June 2003 as amended, the general measures of the Italian supervisory authority and any other applicable provision on the protection of personal data.

b) **"Customer Data"**: the personal data processed by the Provider on behalf of the Customer in providing the Service, as described in Appendix 1. They include the content entered by the Customer's Users, the content acquired from the systems and channels that the Customer connects to the platform and the content generated by the platform from the foregoing, such as summaries, transcripts and search indexes.

c) **"Controller"**: the Customer, which determines the purposes and means of the processing of the Customer Data.

d) **"Processor"**: the Provider, which processes the Customer Data on behalf of the Controller.

e) **"Sub-processor"**: the third party engaged by the Processor for the performance of specific processing activities on behalf of the Controller, pursuant to Article 28, paragraphs 2 and 4, of the GDPR.

f) **"Third-party Services activated by the Controller"**: the third-party services that the Controller connects to the platform with its own credentials, authorisations or parameters, such as the catalogue connectors, the integrations with Microsoft 365 and Google Workspace, the WhatsApp channel, the incoming and outgoing mail servers indicated by the Controller, the endpoints of the Controller's systems to which the platform sends data and the websites reached at the Controller's request by the web page reading tools. Such services are not sub-processors of the Provider: paragraph 3.5 applies.

g) **"Controller's Users"**: the natural persons authorised by the Controller to access the platform.

h) **"Data Subjects"**: the natural persons to whom the Customer Data relate.

i) **"Breach"**: the personal data breach as defined by Article 4, point 12, of the GDPR.

l) **"Digital employee"**: the application instance dedicated to the Controller through which the assistant and automation functions are provided.

Terms not defined in this Annex have the meaning attributed to them by the Conditions or, failing that, by the GDPR.

**1.2 Roles.** In relation to the Customer Data, the Customer acts as Controller and the Provider as Processor. The Customer remains responsible for determining the purposes and the essential means of the processing and for the lawfulness of the data that it enters, or causes to be entered, into the platform.

**1.3 Processing in which the Provider is controller.** The Provider acts as an independent controller, outside this Annex, for the registration and profile data of the Controller's Users, for the billing and payment data, for the usage and diagnostic data necessary for the security and maintenance of the platform, for the audit logs of administrative operations, for the data of the support tickets and for the data of commercial contacts. Such processing operations are described in the notice published at https://evolus.ai/en/privacy-policy. The Provider does not use the Customer Data for its own purposes.

**1.4 Customers managed by a reseller.** A Customer whose account is activated or managed by a reseller accepts this Annex directly and is its sole Controller. The reseller is not a party to this Annex and does not assume, by virtue of it, any status in relation to the Customer Data. Any different relationship between the Customer and the reseller for the processing that the latter carries out on its own behalf or on behalf of the Customer under a separate agreement remains unaffected.

**1.5 Interpretation.** In the event of conflict between this Annex and Annex B, this Annex prevails. Annex B may not be amended so as to reduce the level of security, pursuant to Article 12.5 of the Conditions.

---

## 2. Subject matter, duration, nature and purposes of the processing

**2.1 Subject matter.** The processing has as its subject matter the Customer Data and serves the provision of the Service as described in the Conditions and configured by the Controller in the platform.

**2.2 Nature and purposes.** The processing consists of the operations of collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure and destruction necessary to provide the functions activated by the Controller, including conversational assistance, the automation of activities, the management of the communication channels, the transcription and summarisation of voice conversations and meetings, the search for and retrieval of information from the Controller's documents and interoperability with the Third-party Services activated by the Controller.

**2.3 Categories of data subjects and of data.** They are set out in Appendix 1, which forms an integral part of this Annex.

**2.4 Duration.** The processing lasts for the duration of the Contract and continues, for the return and deletion operations alone, for the periods set out in Article 10.

**2.5 Optional processing operations.** The features that entail further processing, such as the voice agents, the chat widget on the Controller's websites, participation in meetings and the catalogue connectors, are activated by the Controller and processed only if and for as long as the Controller keeps them active.

---

## 3. Documented instructions of the Controller

**3.1 Content of the instructions.** The following constitute documented instructions of the Controller within the meaning of Article 28, paragraph 3, point a), of the GDPR, in the following order:

a) the Conditions and this Annex;

b) the configuration that the Controller or its authorised Users carry out in the platform, including the channels activated, the integrations authorised by granting OAuth authorisations or by means of their own credentials, the retention periods of the voice conversations, the connectors activated and the related credentials, the endpoints to which the platform sends data, the redaction and pseudonymisation criteria and the instructions given to the Digital employees. For Customers on the Enterprise Plan, the choice of the European region of the voice provider, the European routing of the requests to the models, the routing solely to zero-retention endpoints and the definition of the list of permitted model providers also constitute documented instructions; for the other plans the global voice region, global routing and the inference providers on the list published on the page referred to in paragraph 5.2 apply;

c) the further written instructions that the Controller sends to privacy@codedesign.it, which are effective from receipt and are recorded by the Provider.

**3.2 Processing on instructions only.** The Provider processes the Customer Data solely on the basis of the instructions referred to in paragraph 3.1, including in relation to the transfer of data to a third country, unless it is required to do so by Union or Member State law to which it is subject. In that case the Provider informs the Controller before the processing, unless the law prohibits it on important grounds of public interest.

**3.3 Instructions contrary to the Applicable Legislation.** The Provider immediately informs the Controller, at the email address of the administrator indicated by the Controller, if it considers that an instruction infringes the Applicable Legislation. In that case the Provider may suspend the execution of the instruction until the Controller confirms or amends it in writing, and this does not constitute a breach of contract.

**3.4 Instructions exceeding the Service.** Instructions that require activities not provided for by the Service or not achievable with the available features are carried out, where technically possible, subject to agreement between the Parties on reasonable times and costs. The Provider is not required to develop new features in order to act on an instruction.

**3.5 Third-party Services activated by the Controller.** When the Controller activates a Third-party Service with its own credentials or authorisations, the recipient of the data is chosen by the Controller, which is answerable for it as controller of the related processing and sees to the relevant legal basis, the notice to data subjects and, where necessary, its own agreement with that provider. In relation to such transmissions the Provider acts as a mere technical intermediary, on the Controller's instructions, and does not assume the status of controller or of processor for the processing carried out by the third party. The Provider does not select, negotiate or control the contractual and security terms of such third parties, and is not required to verify their compliance.

**3.6 Effects of the configurations.** The Controller acknowledges that some configurations have direct effects on data protection. The retention periods of the voice conversations, the mode without retention, the activation of the connectors and the pseudonymisation and masking criteria are available for all plans. The European region of the voice provider, the European routing of the requests to the models, the routing solely to zero-retention endpoints and the restriction of the model providers for the individual environment are reserved to Customers on the Enterprise Plan; for the other plans the global voice region, global routing and the inference providers on the list published on the page referred to in paragraph 5.2 apply. The features reserved to the Enterprise Plan are available where provided for in the commercial proposal accepted by the Provider, pursuant to Article 2.3 of the Conditions; the plans are described in the price list published at https://evolus.ai/en/pricing. The Provider makes such controls available and documents their effects; the choice and the maintenance of the configuration remain the Controller's.

---

## 4. Obligations of the Processor

The Provider assumes the following obligations, corresponding to points a) to h) of Article 28, paragraph 3, of the GDPR.

### 4.1 Processing on documented instructions (point a)

The Provider processes the Customer Data solely on documented instructions of the Controller, as set out in Article 3.

### 4.2 Confidentiality of the authorised persons (point b)

**4.2.1** The Provider ensures that the persons authorised to process the Customer Data, whether employees or collaborators, have signed confidentiality agreements or are under an appropriate statutory obligation of confidentiality. The obligation continues after the end of the relationship.

**4.2.2** The Provider authorises to the processing only the persons who need it for the provision of the Service, for assistance, for maintenance and for security, and gives them written instructions on the processing.

**4.2.3** Access by the Provider's personnel to the Controller's environments by means of the access on behalf of a User feature is permitted only to expressly enabled profiles, is recorded in the audit log and remains available to the Controller in accordance with Article 4.8.

### 4.3 Security of the processing (point c)

**4.3.1** The Provider adopts the technical and organisational measures adequate to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR. The measures adopted as at the date of acceptance are described in Annex B, which forms an integral part of this Annex.

**4.3.2** The Provider may update the measures in Annex B, provided that the overall level of security is not reduced. The updates are published and communicated in the manner set out in Article 13 of the Conditions.

**4.3.3** The Controller acknowledges that the assessment of the adequacy of the measures in relation to its own purposes, and in particular in relation to the categories of data that it decides to enter into the platform, remains its responsibility, pursuant to Article 8.

### 4.4 Engagement of sub-processors (point d)

Article 5 applies.

### 4.5 Assistance with the rights of data subjects (point e)

**4.5.1** Taking into account the nature of the processing, the Provider assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from data subjects under Chapter III of the GDPR.

**4.5.2** The Provider does not respond directly to requests from data subjects relating to the Customer Data. If it receives a request from a data subject relating to Customer Data, the Provider forwards it to the Controller, at the email address of the administrator and to the contact persons indicated in Appendix 4, within 5 working days of receipt, informs the data subject that it has been forwarded and provides no other substantive response, unless otherwise instructed in writing by the Controller.

**4.5.3** The assistance includes, upon written request of the Controller and within the limits of the available features, the search for the data relating to a data subject, their extraction in a readable format, their rectification and their erasure. The Parties acknowledge that extraction and erasure relating to an individual data subject are not available as a feature of the platform and are carried out by the Provider upon written request, with assisted intervention and within times agreed on a case-by-case basis.

**4.5.4** The assistance is provided at no additional cost for a reasonable number of requests. For requests that are manifestly excessive in number or complexity the Provider may ask for a fee commensurate with the effort, agreed in advance.

### 4.6 Assistance with the obligations under Articles 32 to 36 (point f)

**4.6.1** The Provider assists the Controller, taking into account the nature of the processing and the information available to it, in ensuring compliance with the obligations of security of processing, of notification and communication of Breaches, of data protection impact assessment and of prior consultation of the supervisory authority.

**4.6.2** For Breaches, Article 9 applies.

**4.6.3** Upon written request of the Controller, the Provider makes available the description of the processing architecture, of the security measures, of the data flows and of the sub-processors that the Controller needs in order to carry out its own impact assessment. The Provider does not carry out the impact assessment on behalf of the Controller and does not assume its outcome.

### 4.7 Deletion or return at the end (point g)

Article 10 applies.

### 4.8 Information and audit activities (point h)

**4.8.1** The Provider makes available to the Controller all the information necessary to demonstrate compliance with the obligations of this Annex and of Article 28 of the GDPR.

**4.8.2** The Controller may carry out one audit per calendar year, with written notice of at least 30 days, save in the case of an established Breach involving the Customer Data, in which case the audit may be carried out without the frequency limit and with 7 days' notice.

**4.8.3** The audit is carried out in the first place in documentary or remote form, by means of the transmission of the documentation on the measures adopted, of the available internal audit reports and of the answers to a security questionnaire. An on-site audit at the Provider's premises is permitted where the documentary or remote audit is not sufficient to clarify a specific finding, and takes place during office hours, for the time strictly necessary, without prejudice to the continuity of the Service and without access to the data of other customers of the Provider.

**4.8.4** The costs of the audit are borne by the Controller, including those of the third party engaged by the Controller, unless the audit establishes a Breach attributable to the Provider or a material failure to comply with this Annex, in which case the costs are borne by the Provider.

**4.8.5** The Controller and the third parties it engages are bound to confidentiality as to what they learn. The third party may not be a competitor of the Provider. The Provider may object, on reasoned grounds, to the designation of a third party, and in that case the Parties agree on an alternative one.

**4.8.6** The Provider is not required to allow access that would prejudice the security or confidentiality of the data of other customers, the security of its own infrastructure or confidentiality obligations towards third parties.

**4.8.7** The Provider declares that it has started a certification process for its information security management system according to the ISO/IEC 27001:2022 standard. As at the date of this Annex the certification has not been obtained and the Provider does not declare it as obtained. Its achievement will be communicated to Customers and set out in Annex B.

### 4.9 Record of the categories of processing activities

The Provider keeps the record of the categories of processing activities carried out on behalf of the Controller, pursuant to Article 30, paragraph 2, of the GDPR, and makes available to the Controller the extract relating to the processing operations that concern it, upon written request.

### 4.10 Contact point

**4.10.1** The Provider has not designated a data protection officer pursuant to Article 37 of the GDPR, having assessed that the statutory conditions do not apply. The assessment is reviewed at least annually.

**4.10.2** The contact point for any matter relating to this Annex, for the written instructions of the Controller, for requests from data subjects and for communications relating to Breaches is the privacy@codedesign.it mailbox, monitored by the Provider's data protection contact person.

---

## 5. Sub-processors of the processing

**5.1 General authorisation.** The Controller gives the Provider general authorisation to engage sub-processors for the performance of specific processing activities, pursuant to Article 28, paragraph 2, of the GDPR.

**5.2 List.** The updated and versioned list of the sub-processors, indicating the name, the country of establishment, the activity performed and the categories of data processed, is published at https://evolus.ai/en/subprocessors. A snapshot of the list as at the date of this Annex is set out in Appendix 2. In the event of discrepancy the published list prevails.

**5.3 Communication of changes.** The Provider communicates to the Controller, at the email address of the administrator indicated by the Controller and by means of a notice in the portal, any addition or replacement of sub-processors, with at least 30 days' notice before the date envisaged for the start of the processing by the new sub-processor. The communication indicates the name of the sub-processor, the country of establishment, the activity entrusted, the categories of data concerned and, in the case of a transfer outside the European Union, the legal basis of the transfer.

**5.4 Objection.** Within 30 days of the communication the Controller may object on reasonable and documented grounds connected with the protection of personal data, by writing to privacy@codedesign.it. The Parties shall cooperate in good faith to identify an alternative solution, such as a different configuration of the Service that excludes the contested sub-processor. Where such a solution is not possible, the Controller may withdraw from the Contract limited to the Services concerned, without penalties and with a proportional refund of the fees paid for the unused period, in accordance with Article 12.6 of the Conditions.

**5.5 Urgent replacements.** Where the replacement of a sub-processor is required for reasons of security, by the sudden cessation of the service by the provider or by a measure of the authorities, the Provider may proceed with it without the notice referred to in paragraph 5.3, notifying the Controller within 5 days of the activation. The right to object and the right of withdrawal under paragraph 5.4 remain unaffected and may be exercised within 30 days of the communication.

**5.6 Contractual chain.** The Provider imposes on each sub-processor, by contract or other legal act, data protection obligations no less onerous than those of this Annex, in particular as regards the confidentiality of personnel, adequate security measures, purpose limitation, assistance to the Provider, notification of breaches without undue delay, deletion or return of the data at the end and the prohibition on engaging further sub-processors without equivalent guarantees.

**5.7 Liability for the sub-processor.** Where a sub-processor fails to fulfil its data protection obligations, the Provider remains fully liable to the Controller for the performance of that sub-processor's obligations, pursuant to Article 28, paragraph 4, of the GDPR.

**5.8 Sub-processors activated by the Controller.** The Third-party Services activated by the Controller referred to in paragraph 3.5 are not sub-processors of the Provider, even where they appear in the catalogue of connectors made available by the platform. The catalogue is a configuration tool: the choice of the provider and the entry of the related credentials are acts of the Controller.

---

## 6. Transfers of personal data outside the European Union

**6.1 Transparency statement.** The Controller acknowledges that the provision of the Service currently entails transfers of personal data to third countries. The Provider does not represent that the Customer Data remain entirely within the European Economic Area.

**6.2 Infrastructure.** The infrastructure for the processing and storage of the Customer Data is located in the European Union. In particular: the application services, the database, the file storage and the vector store of the document indexes are hosted on cloud infrastructure in Western Europe; the Digital employees, their memory and their local archives are hosted on a server located in Germany; the backups are kept on object storage located in Finland; the optical character recognition of documents is carried out on cloud infrastructure in a European Union region. The precise locations are indicated in Appendix 1, section "Places of processing".

**6.3 Providers of artificial intelligence models.** The requests to the language models are routed through OpenRouter, Inc., a company established in the United States of America, which assigns them to one of the inference providers permitted on the Provider's account. The list of permitted providers is published on the page referred to in paragraph 5.2 and is set out, as at the date of this Annex, in Appendix 2. The content transmitted includes the text of the conversation, the attachments and the outputs of the tools used. The assignment takes place for each individual request: the configuration of the Service identifies the model requested and not the provider that executes it, and for some features the model itself is selected dynamically by the routing service. A Controller on the Enterprise Plan may restrict the list of permitted providers for its own environment pursuant to paragraph 6.8 and obtain European routing and routing solely to zero-retention endpoints pursuant to paragraph 6.7.

**6.4 Voice and transcription services.** The voice synthesis, voice agent and meeting diarisation features are provided by ElevenLabs, a company established in the United States of America. The European region of residence of the voice data is available to Customers on the Enterprise Plan; for the other plans the global region applies. For the shared voice subscriptions made available by the Provider the global region applies in any event. The default voice transcription and the voice synthesis on the WhatsApp channel are provided by Deepgram, Inc., a company established in the United States of America, on a global endpoint.

**6.5 Legal bases of the transfer.** The transfer to each recipient takes place, in the following order:

a) on the basis of an adequacy decision of the European Commission pursuant to Article 45 of the GDPR, where applicable to the country of the recipient;

b) for recipients established in the United States of America, on the basis of the adequacy decision relating to the EU-US Data Privacy Framework, where the entity is certified in the official register and for the categories of data covered by the certification;

c) in the absence of the conditions under points a) and b), on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, module 3 (processor to processor), incorporated into the agreement between the Provider and the provider concerned and supplemented by any supplementary measures that may be necessary;

d) residually, on the basis of one of the derogations under Article 49 of the GDPR, where the conditions for it are met and for the time strictly necessary.

The Provider does not represent that all the recipients established in the United States of America are certified under the EU-US Data Privacy Framework. The certification status of each recipient is verified in the official register, is indicated on the page referred to in paragraph 5.2 and is updated at each change. For recipients that are not certified, point c) applies.

**6.6 Transfer impact assessment.** The Provider documents, for each transfer based on point c) of paragraph 6.5, a transfer impact assessment that takes into account the legislation and practices of the country of destination, the categories of data transferred and the supplementary measures adopted. The assessment is made available to the Controller upon written request, within the limits of Article 4.8.

**6.7 Features that reduce transfers, reserved to the Enterprise Plan.** The following are available to Customers on the Enterprise Plan, where provided for in the commercial proposal accepted by the Provider pursuant to Article 2.3 of the Conditions: the European routing of the requests to the models, by means of the European Union endpoint of the routing service; the routing solely to zero-retention endpoints; the restriction of the permitted model providers for the individual environment; the European region of the voice provider. For the other plans, global routing, the inference providers on the list published on the page referred to in paragraph 5.2 and the global voice region apply. The Provider reports on that same page the status of each feature and undertakes to activate European routing with each provider that makes it available on the technical and economic terms of the Service.

**6.8 Exclusion of recipients.** The limitation of the list of permitted model providers for one's own environment is available to Customers on the Enterprise Plan; for the other plans the inference providers on the list published on the page referred to in paragraph 5.2 apply. Where activated, the limitation prevails over the preferences set at the level of the individual feature. The Provider gives effect to the limitation with the controls made available in the platform; where the limitation makes a feature technically unavailable, the Provider informs the Controller and the feature remains suspended.

**6.9 Cooperation.** The Parties shall cooperate in good faith if an adequacy decision is annulled or suspended, or if the supervisory authority adopts a measure that affects the transfers in place, in order to identify without delay an alternative legal basis or a different configuration of the Service. Where this is not possible, the right of withdrawal under paragraph 5.4 applies.

---

## 7. Use of artificial intelligence systems

**7.1 No training by the Provider.** The Provider does not use the Customer Data to train, retrain, fine-tune or evaluate artificial intelligence models of its own, nor for purposes other than the provision of the Service to the Controller.

**7.2 Commitment towards the sub-processors.** The Provider undertakes to select sub-processors that provide the artificial intelligence services while contractually excluding the use of the content transmitted for the training of their own models, and to activate, with the providers that allow it, the service settings that disable the retention and the use of the content for their own purposes, including the opt-out parameters to be transmitted with each individual request where the provider offers that method. The Provider reports on the status of such commitments on the page referred to in paragraph 5.2.

**7.3 Nature of the outputs.** The outputs generated by the models may be inaccurate or incomplete. The Service is a support and automation tool: the Controller retains oversight of the outputs and verifies their reliability before relying on them for significant decisions.

**7.4 No automated decision-making within the meaning of Article 22.** The Service is not designed to take decisions based solely on automated processing which produce legal effects concerning data subjects or similarly significantly affect them. Where the Controller configures the Service so as to produce such an effect, the related processing is attributed to its exclusive determination and the Controller assumes the obligations under Article 22 of the GDPR, including the provision of safeguards and of human intervention.

**7.5 Declaration of artificial nature.** The Service applies a declaration of artificial nature in the communications generated towards third parties, which the Controller cannot disable, and retains proof of it. The Controller shall not circumvent, and shall not cause others to circumvent, that declaration.

**7.6 Notices of the Controller towards its own data subjects.** The Controller informs its own Users, employees, customers and contacts that their data are processed by means of the platform and transmitted to the artificial intelligence providers indicated in the list of sub-processors, and of the purposes of the processing. The Provider makes available to the Controller model texts that may be used for this purpose, such as the model addendum to the notice to employees and the model notice for callers and for website visitors, contained in the document "Templates for customers" made available in the portal. The models are a support tool and do not relieve the Controller of assessing their adequacy for its own context.

---

## 8. Obligations of the Controller

**8.1 Lawfulness.** The Controller warrants that the Customer Data are collected and processed lawfully, that there is an appropriate legal basis for each purpose and that the instructions given to the Provider comply with the Applicable Legislation.

**8.2 Notices.** The Controller provides data subjects with the notices required by Articles 13 and 14 of the GDPR, including the indication of the engagement of a processor, of the categories of recipients and of the transfers to third countries described in Article 6.

**8.3 Configurations.** The Controller makes and maintains the configurations of the platform consistent with its own determinations on data protection, in accordance with paragraph 3.6, and periodically verifies their adequacy.

**8.4 Special categories of data.** The Service is not designed for the systematic processing of the special categories of personal data referred to in Article 9 of the GDPR or of the data relating to criminal convictions and offences referred to in Article 10. The Controller may enter or route such data only if it ensures their lawfulness, if one of the conditions of Article 9, paragraph 2, or of Article 10 applies, and if it adopts the further measures that the risk requires, including the pseudonymisation and redaction features made available by the platform. The Controller acknowledges that such data may appear incidentally in the content of emails, in documents, in voice transcripts and in conversations.

**8.5 Third-party data present in the connected channels.** The Controller warrants that it is entitled to allow the Provider access to the mailboxes, calendars, document archives and messaging channels that it connects to the platform, and that it has informed the data subjects whose data are contained in them, including third-party senders and recipients of the communications.

**8.6 Monitoring of workers.** The Controller, where it is an employer, uses the Service in compliance with Article 4 of Law No. 300 of 20 May 1970 and with the applicable national rules on remote monitoring, fulfils the related obligations of trade union agreement or administrative authorisation when due and informs workers of the manner of use of the tools and of the manner in which checks are carried out, pursuant to Article 4, paragraph 3, of that same Law. The Provider is not a party to those obligations and is not answerable for them.

**8.7 Users.** The Controller manages the authorisations of its own Users, promptly revokes those that are no longer necessary, safeguards the credentials and gives its Users instructions on the use of the platform.

**8.8 Contact persons.** The Controller keeps up to date in the portal the contact details of the administrator and of the data protection contact persons indicated in Appendix 4, to whom the Provider sends the communications provided for by this Annex.

**8.9 Indemnity.** The Controller holds the Provider harmless from third-party claims, including the penalties of the supervisory authority, that arise from the breach of the obligations under this Article, within the limits of Article 11.

---

## 9. Personal data breaches

**9.1 Notification to the Controller.** The Provider notifies the Controller of any Breach concerning the Customer Data without undue delay and in any event within 48 hours of becoming aware of it, regardless of the level of risk established. The assessment of the risk to data subjects and the decision on notification to the supervisory authority and on communication to data subjects are for the Controller.

**9.2 Moment of awareness.** The Provider becomes aware of the Breach at the moment when it acquires a reasonable degree of certainty that a security incident with an impact on personal data has occurred. The period of investigation is as short as possible and is documented. Where the Breach is communicated to the Provider by a sub-processor, the Provider is aware of it at the moment of receipt of the communication.

**9.3 Content of the notification.** The notification contains, pursuant to Article 33, paragraph 3, of the GDPR:

a) the description of the nature of the Breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

b) the name and contact details of the contact point where more information can be obtained, which is the privacy@codedesign.it mailbox;

c) the description of the likely consequences of the Breach;

d) the description of the measures taken or proposed to be taken to address the Breach and to mitigate its possible adverse effects;

e) the date and time of the Breach and of its discovery, the systems and features involved and any actions that the Controller must take.

**9.4 Preliminary notification and updates.** Where, on the expiry of the 48 hours, the information is not available in full, the Provider notifies what has been established, expressly qualifying the communication as preliminary, and transmits the updates as the information consolidates, and in any event at least every 72 hours for as long as the case remains open.

**9.5 Channels.** The notification is sent to the email address of the administrator indicated by the Controller and to the contact persons in Appendix 4, and is accompanied by the opening of a ticket in the support portal, which keeps track of the communication and of the replies. For Breaches involving several customers or the common infrastructure the Provider publishes a notice on the status page of the Service.

**9.6 Assistance.** The Provider assists the Controller, upon written request and without delay, by providing the technical information necessary for the Controller's notification to the supervisory authority and for the communication to data subjects. The Provider does not make the notification to the authority or the communication to data subjects in the name of the Controller, save under a specific written mandate.

**9.7 Containment and documentation.** The Provider adopts containment and remedial measures without delay, retains the evidence of the event and documents every Breach in an internal register, including the circumstances, the effects and the measures adopted. The Provider sends the Controller a final communication on the outcome of the investigation within 30 days of the closure of the case.

**9.8 Breaches at the sub-processors.** Breaches that occur at a sub-processor and involve the Customer Data are handled with the same procedure and the same time limits, which run from the receipt of the sub-processor's communication.

**9.9 Breaches not attributable to the Provider.** The notification referred to in paragraph 9.1 does not constitute an acknowledgement of liability on the part of the Provider. Breaches that concern exclusively the Controller's systems or the Third-party Services activated by the Controller are excluded from the notification obligation; the Provider nonetheless informs the Controller of them where it becomes aware of them.

**9.10 Procedure.** The Provider maintains a documented procedure for the management of personal data breaches, with roles, time limits, channels and communication templates, reviewed at least annually. The procedure is made available to the Controller in extract form, upon written request, within the limits of Article 4.8.

---

## 10. Deletion and return of the data at the end

**10.1 Choice of the Controller.** Upon termination of the Contract, on whatever ground, the Provider, at the Controller's choice, returns the Customer Data or deletes them, and deletes the existing copies, unless Union or Member State law requires the storage of the data.

**10.2 Exercise of the choice.** The Controller communicates its choice to privacy@codedesign.it within 30 days of the termination. In the absence of a communication within that period the Provider proceeds with the deletion, following a written reminder with at least 10 days' notice.

**10.3 Return.** The return takes place by making the Customer Data available in the following formats: documents and recordings in the original files; conversations, transcripts and structured data in an open, machine-readable format, JSON or CSV. Delivery takes place by means of an encrypted archive, with the key transmitted over a separate channel, available for collection for 30 days. The return does not include the elements that constitute intellectual property of the Provider, the internal configurations of the platform and the data of other customers.

**10.4 Time limits for the deletion.** The deletion of the Customer Data from the production systems is completed within 60 days of the termination of the Contract, or of the making available of the export if later. The copies present in the backups are overwritten by the normal rotation cycle within a further 30 days, for an overall maximum period of 90 days from the termination. For the entire period access to the Customer Data is blocked and the data are not used for any purpose other than technical storage and their deletion.

**10.5 Content of the deletion.** The deletion covers the conversations and messages, the documents and attachments and the related search indexes, the transcripts and recordings, the address books and registry records, the configurations and instructions, the credentials and authorisations granted to the connectors, and the local archives of the Digital employee, including its working volumes.

**10.6 Retention for legal obligations.** The Provider may retain the Customer Data beyond the periods set out in paragraph 10.4 only to the extent and for the time required by a legal obligation, informing the Controller of it with an indication of the applicable rule, of the category of data retained and of the period. The data so retained are subject to restriction of processing and are not used for any other purpose.

**10.7 Residual non-identifying technical data.** The Provider may retain, beyond the periods set out in paragraph 10.4, the aggregated or non-identifying data necessary for invoicing, for demonstrating compliance and for security, including the audit logs of administrative operations for the periods set out in Annex B, the consumption details without identifying references and the residual technical rows of the voice conversations, without audio, transcript, summary or caller's number, kept for the sole purpose of demonstrating that the declaration of artificial nature was made and of avoiding duplication at the import stage.

**10.8 Attestation.** On completion of the operations the Provider issues to the Controller, upon written request, an attestation that the deletion has taken place, indicating the categories of data deleted and the date.

**10.9 Suspension of access.** The suspension of access to the platform provided for by the Conditions does not entail the deletion of the Customer Data, which remain retained until the termination of the Contract and, from that moment, in accordance with the time limits of this Article.

---

## 11. Liability

**11.1 Reference.** The liability of the Provider for failure to comply with this Annex is governed by Article 7 of the Conditions, specifically approved by the Customer pursuant to Article 1341, paragraph 2, of the Italian Civil Code.

**11.2 Mandatory limits.** The limitations and exclusions of liability in Article 7 of the Conditions do not apply in the cases in which the law prohibits their operation, and in particular in the case of wilful misconduct or gross negligence, of personal injury and in the cases in which the Applicable Legislation excludes any contractual limitation.

**11.3 Allocation pursuant to Article 82 of the GDPR.** As between the Parties, each bears the economic consequences of the damage caused by the processing to the extent to which it is attributable to it pursuant to Article 82 of the GDPR. The Provider is liable for the damage caused by the processing only where it has not complied with the obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the lawful instructions of the Controller.

**11.4 Recourse.** The Party that has paid full compensation for the damage is entitled to claim back from the other the part corresponding to the latter's liability, pursuant to Article 82, paragraph 5, of the GDPR.

**11.5 Penalties.** The administrative fines imposed by the supervisory authority remain the responsibility of the Party to which the measure refers. Where the measure establishes the concurrent liability of both, each bears the share corresponding to its own conduct.

---

## 12. Duration, amendments, applicable law and jurisdiction

**12.1 Duration.** This Annex is effective from the date of acceptance and remains in force for the entire duration of the Contract and, for the provisions of Articles 10 and 11, until the completion of the return and deletion operations.

**12.2 Amendments.** The Provider may amend this Annex in the manner and with the notice periods set out in Article 13 of the Conditions. The new versions apply in the manner set out in paragraphs 3.10 and 13.3 of the Conditions. Where the amendment entails a worsening of the guarantees on data protection, the Controller may withdraw without penalties in accordance with Article 13.2 of the Conditions.

**12.3 Amendments required by law.** Amendments required by legal rules, by measures of the supervisory authority or by developments in the adequacy decisions may be applied with immediate effect, with a communication to the Controller within 5 days of their application, pursuant to Article 13.4 of the Conditions.

**12.4 Partial invalidity.** The invalidity of an individual provision does not affect the effectiveness of the remaining ones. The Parties shall replace the invalid provision with one of the most nearly equivalent economic and legal effect that complies with the Applicable Legislation.

**12.5 Applicable law.** This Annex is governed by Italian law and is to be interpreted in accordance with the GDPR and with the guidelines of the European Data Protection Board.

**12.6 Jurisdiction.** For any dispute relating to this Annex the Court of Imperia has exclusive jurisdiction, in accordance with Article 14.4 of the Conditions, without prejudice to clause 18 of the Standard Contractual Clauses for the disputes that fall within it and without prejudice to the right of the data subject to bring proceedings in the forums provided for by Article 79 of the GDPR.

---

# Appendix 1. Details of the processing

## 1.1 Summary table

| Item | Content |
| --- | --- |
| **Subject matter** | Processing of the Customer Data necessary for the provision of the Evolus platform and of the features activated by the Controller |
| **Duration** | Duration of the Contract, plus the return and deletion periods set out in Article 10 |
| **Nature** | Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure, destruction |
| **Purposes** | Conversational assistance and automation of activities; management of the Controller's communication channels; transcription, diarisation and summarisation of voice conversations and meetings; indexing and retrieval of information from the Controller's documents; interoperability with the Third-party Services activated by the Controller; provision of the features of the mobile application; technical assistance at the Controller's request; security of the Service and prevention of abuse |
| **Type of processing** | Automated, with authorised and logged manual interventions for assistance and maintenance |
| **Frequency** | Continuous for the duration of the Contract |

## 1.2 Categories of data subjects

a) Users of the Controller authorised to access the platform.

b) Employees and collaborators of the Controller whose data appear in the content processed, in the address books, in the calendars and in the communications.

c) Customers, prospective customers and commercial contacts of the Controller.

d) Suppliers, consultants and partners of the Controller.

e) Visitors to the Controller's websites who interact with the chat widget.

f) Callers and called parties of the voice agents and of the switchboard, where the feature is activated.

g) Participants in the meetings that the platform assists with, where the feature is activated.

h) Senders, recipients and persons mentioned in the emails, in the calendars and in the conversations of the connected channels.

i) Third parties whose personal data are contained in the documents, in the attachments and in the content entered into the platform.

## 1.3 Categories of personal data

a) Identification and contact data: first name, last name, username, email address, telephone number, role, organisation of membership, preferred language, profile image.

b) Content of communications: emails with their attachments, chat conversations of the portal and of the widget, messages on the connected messaging channels, including Microsoft Teams and WhatsApp, drafts and replies generated.

c) Calendar data: events, times, places, participants, subject and description.

d) Documents and files: documents uploaded to the knowledge libraries, attachments of the conversations and of the tickets, files generated by the platform, with their metadata and search indexes.

e) Voice data: audio recordings of the calls and of the meetings, transcripts, speaker diarisation, summaries and analyses, telephone number of the caller and of the called party.

f) Data of interaction with the chat widget: content of the messages, name and contact details possibly provided by the visitor, address of the page visited, title of the page and internal links of the page transmitted to the Service in order to provide the context of the reply.

g) Technical and usage data: session and device identifiers, IP address, browser identifier, access and activity logs, diagnostic data, audit logs of administrative operations, data on the consumption of the Service.

h) Configuration data: instructions, automations, rules, address books, lists of recipients and credentials of the Third-party Services activated by the Controller, kept in encrypted form.

i) Special categories of data within the meaning of Article 9 of the GDPR and data relating to criminal convictions and offences within the meaning of Article 10, only where contained incidentally in the content entered or acquired, on the terms and within the limits of paragraph 8.4.

## 1.4 Places of processing

| Processing | Place |
| --- | --- |
| Application services, database, file storage and key store | Cloud infrastructure, Western Europe (European Union) |
| Identity and authentication system | Cloud infrastructure, Western Europe (European Union) |
| Vector store of the document indexes | Platform database, Western Europe (European Union) |
| Optical character recognition of documents | Cloud infrastructure, European Union region |
| Digital employees, their local archives, orchestration, meeting and telephony services | Dedicated server, Nuremberg, Germany |
| Backups | Object storage, Helsinki, Finland |
| Observability and technical logs | Monitoring infrastructure managed by the Provider, European Union |
| Translation of the summaries of the calls | Model service on cloud infrastructure, France |
| Routing of the requests to the language models and downstream inference providers | European endpoint of the routing service for Customers on the Enterprise Plan; for the other plans the global endpoint, with processing in the United States of America and in other countries, according to the list in Appendix 2 and on the page referred to in paragraph 5.2 |
| Voice services, synthesis and diarisation | European region for Customers on the Enterprise Plan; global region for the other plans and for the shared voice subscriptions |
| Default voice transcription and voice synthesis on the WhatsApp channel | United States of America, global endpoint |
| Notifications to mobile devices | United States of America, notification transport services |

---

# Appendix 2. Sub-processors of the processing

The binding and up-to-date list is the one published at https://evolus.ai/en/subprocessors, version 1.0 of 21 September 2026. This appendix reproduces the snapshot of the list as at the date of this Annex, for the purposes of transparency and of documenting the acceptance.

## 2.1 Structural sub-processors

They process Customer Data by the mere fact that the Service is provided, without any activation by the Controller being required.

| Sub-processor | Activity | Place of processing | Categories of data |
| --- | --- | --- | --- |
| Microsoft Ireland Operations Limited, Ireland, an entity of the Microsoft Corporation group, United States | Cloud infrastructure: application services, database, file storage, key store, image registry, observability, optical character recognition of documents, translation of the summaries of the calls, sending of the service mail, communication services for integrated telephony | European Union (Western Europe and France) | All the categories in Appendix 1.3 |
| Hetzner Online GmbH, Germany | Dedicated server of the Digital employees, orchestration, meeting and telephony services, object storage of the backups | Germany and Finland | All the categories in Appendix 1.3 |
| OpenRouter, Inc., United States | Routing of the requests to the language models | European endpoint for Customers on the Enterprise Plan; global endpoint, with processing in the United States of America, for the other plans | Content of the conversations, attachments, outputs of the tools, technical identifiers of the request |
| Inference providers permitted downstream of OpenRouter, Inc., as at the date: Amazon Web Services, Inc., United States; Anthropic PBC, United States; Microsoft Corporation, United States; Fireworks AI, Inc., United States; Google LLC, United States; NVIDIA Corporation, United States; OpenAI Global LLC, United States; Parasail, Inc., United States; Perplexity AI, Inc., United States; Recraft AI Limited, United Kingdom. The providers established in countries without an adequacy decision are excluded from routing | Execution of the inference on the models requested | United States of America and United Kingdom, according to the provider assigned | Content of the conversations, attachments, outputs of the tools |
| ElevenLabs, United States | Voice synthesis, voice agents, diarisation of the meetings | European region for Customers on the Enterprise Plan; global region for the other plans and for the shared voice subscriptions | Audio, transcripts, caller's number, text to be spoken |
| Deepgram, Inc., United States | Default voice transcription, voice synthesis on the WhatsApp channel | United States of America | Audio and transcripts |
| 650 Industries, Inc. (Expo), United States | Sending of the notifications to the mobile devices | United States of America | Device identifier, title and content of the notification |
| Apple Inc., United States, and Google LLC, United States | Transport of the notifications to iOS and Android devices | United States of America and European Union | Device identifier, content of the notification |
| Internet Security Research Group (Let's Encrypt), United States | Issuance of the security certificates for the connections | United States of America | Domain names, no content data |

> **Warning on the inference providers.** The assignment of the individual request to one of the permitted providers is made by the routing service. The list set out here is taken from the panel of the Provider's account as at 19 September 2026, can be changed from that same panel without any software release and is therefore taken afresh with each new version of the page referred to in paragraph 5.2. The providers established in countries without an adequacy decision are excluded from routing with effect from the effective date of this Annex. A Controller on the Enterprise Plan may restrict the list of permitted providers for its own environment pursuant to paragraph 6.8.

## 2.2 Sub-processors activated at the Controller's choice

They process Customer Data only if the Controller activates the corresponding feature or configuration.

| Sub-processor | Activity | Condition for activation |
| --- | --- | --- |
| AssemblyAI, Inc., United States | Alternative voice transcription | Selection of the transcription provider by the Controller |
| OpenAI Ireland Limited, Ireland, and OpenAI Global LLC, United States | Alternative voice transcription and direct call to the models on the features that provide for it | Selection of the transcription provider or configuration of the model |
| Microsoft Ireland Operations Limited, Ireland, and Microsoft Corporation, United States; Google LLC, United States; Perplexity AI, Inc., United States; Exa Labs, United States; Parallel Web Systems, Inc., United States | Search for information on the web at the assistant's request | Activation of the search feature on the agent and choice of the engine |

The vector store of the document indexes is hosted on the platform database, in the European Union, and does not entail the engagement of a further sub-processor.

## 2.3 Entities that are not sub-processors of the Provider

The Third-party Services activated by the Controller referred to in paragraph 3.5, including the catalogue connectors activated with the Controller's credentials, Microsoft 365 and Google Workspace, Meta Platforms for the WhatsApp channel, the Controller's incoming and outgoing mail servers, the endpoints of the Controller's systems to which the platform sends data and the websites reached by the web page reading tools, are not sub-processors of the Provider. The Provider nonetheless discloses them on the page referred to in paragraph 5.2, for the purposes of transparency.

The providers that process data on behalf of the Provider in its capacity as independent controller within the meaning of paragraph 1.3, including the payment services provider and the Provider's administrative management system, do not process Customer Data within the meaning of this Annex and are indicated in the notice referred to in paragraph 1.3.

---

# Appendix 3. Technical and organisational measures

The technical and organisational measures adopted by the Provider pursuant to Article 32 of the GDPR are described in **Annex B, Technical and Organisational Measures**, version 1.0, published at https://evolus.ai/en/security-measures, which forms an integral part of this Annex and is deemed to be fully referred to here.

The measures required of the sub-processors are those set out in Article 5.6. The measures that the Controller may configure in the platform to protect its own data subjects are described in section 11 of Annex B.

---

# Appendix 4. Contacts and contact persons

## 4.1 Contact persons of the Provider

| Role | Contact details |
| --- | --- |
| Data protection contact point | privacy@codedesign.it |
| Communications relating to personal data breaches | privacy@codedesign.it |
| Written instructions of the Controller pursuant to paragraph 3.1, point c) | privacy@codedesign.it |
| Audit requests pursuant to Article 4.8 | privacy@codedesign.it |
| Data protection officer | Not designated, pursuant to paragraph 4.10.1 |

## 4.2 Contact persons of the Controller

The following data are filled in and kept up to date by the Controller in the portal, in the section dedicated to the data protection contact persons. In the absence of an indication, communications are sent to the email address of the administrator of the organisation registered on the platform.

| Role | Data to be indicated |
| --- | --- |
| Administrator of the organisation | Name and email address |
| Data protection contact person of the Controller | Name and email address |
| Data protection officer of the Controller, if designated | Name, email address and telephone contact |
| Contact for urgent communications relating to breaches | Telephone contact |
| Representative in the Union pursuant to Article 27 of the GDPR, if any | Name and contact details |

---

*Annex A, version 1.0. CodeDesign S.r.l., Via Nino Pesce 38, 18018 Taggia (IM), VAT No. IT01739830089. Data protection contact: privacy@codedesign.it.*
