Varren Data Processing Addendum

Alpha Innovation Technologies - F.Z.C, a free zone company registered in Ajman Free Zone, Ajman, United Arab Emirates, trading as AlphaIT Engineering Effective date: 22 September 2026 Version: 1.1 Applies to: varren.co, the Varren application, the Varren API, and every Varren service (together, the "Service")

1. Scope and precedence

This Data Processing Addendum (the "Addendum") governs the processing of personal data carried out on your behalf. It forms part of the Varren Terms of Service (the "Terms") and is incorporated into them by reference. Acceptance of the Terms constitutes acceptance of this Addendum, which takes effect at that moment. No signature is required.

Where your procurement requires a countersigned copy, write to [email protected] with your legal entity name and registered address, and we will return a signed PDF of this text within five business days. We provide one standard form and do not negotiate variants.

Order of precedence. On the processing of Customer Personal Data, the order is: the Standard Contractual Clauses in section 8; then this Addendum; then the Terms; then the Privacy Policy. An addendum or order form signed by both parties prevails over this Addendum but not over the Standard Contractual Clauses. Where clause 37.3 of the Terms gives the Privacy Policy precedence on matters of personal data, that is read subject to this paragraph for personal data we process on your behalf: the Privacy Policy is a notice describing the processing we carry out as a controller and does not vary, reduce or override this Addendum. The joint controllership of the likeness consent record and the withdrawal route in section 3 is not displaced by any document that ranks above the Privacy Policy here.

2. Definitions

"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as it forms part of United Kingdom law under the European Union (Withdrawal) Act 2018, with the Data Protection Act 2018.

"Data Protection Law" means every data protection law applying to either party in connection with the Service, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, United Arab Emirates Federal Decree-Law No. 45 of 2021, the Nigeria Data Protection Act 2023 with its General Application and Implementation Directive 2025 ("GAID 2025"), the Kenya Data Protection Act 2019 with its regulations, and the United States state privacy laws in section 19, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act ("CCPA").

"Customer Personal Data" means personal data in the material you upload, in the accounts you connect and in the instructions you give, which we process on your behalf. Other defined terms carry their GDPR meanings, and where your law names the same thing differently, the equivalent term is meant. Under the United States state privacy laws in section 19, Customer Personal Data is "personal information", you are the "business" or "controller", and we are the "service provider" or "processor".

"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. "UK Addendum" means the International Data Transfer Addendum to those clauses, version B1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022.

3. Roles

You are the controller of Customer Personal Data. We are your processor. You decide what to upload, which accounts to connect, whom to contact and what Varren does. We carry out those instructions.

Where you are yourself a processor, for example an agency acting for its own clients, we are your sub-processor, everything here applies unchanged, and the transfer terms switch from module two to module three of the SCCs automatically. You confirm that your client has authorised you to appoint us.

We are a controller for a separate set of data: account and login records, billing records, security and fraud signals, support correspondence and service telemetry. The Privacy Policy at https://varren.co/privacy governs that data, which is not Customer Personal Data.

We do not act as joint controllers, with one exception set out below. On every processing operation in Annex 1 you determine the purposes and we act only on your instructions, including where Varren acts autonomously on a platform under a mandate you granted and can withdraw. Where a supervisory authority or a court finds that we jointly determine the purposes and means of a particular operation, we will agree with you the arrangement Article 26 of the GDPR requires for that operation, allocating responsibility in line with each party's actual role, and the rest of this Addendum continues to apply.

The exception: the likeness consent record and the withdrawal route. Where you use the likeness and voice feature governed by Section 12 of the Privacy Policy, you and we are joint controllers under Article 26 of the GDPR for two things only: the record of the depicted person's consent, and the route by which that person can contact us and withdraw it. Everything else about that feature runs on the ordinary split in this section. You are the controller of the reference material and of the decision to generate, and you are responsible for having obtained the consent. We are your processor for the generation. We operate the withdrawal route at [email protected] so that the depicted person has a route to us, we act on contact from them, and we inform you when we do. The depicted person may approach either party and exercise their rights against either party, whether or not they are your customer or ours, and neither party may direct them to the other as a reason not to act.

This exception is a floor and is not a variation you can contract out of. The essence of the arrangement, as Article 26(2) requires, is this paragraph together with Section 12 of the Privacy Policy, and we make it available to the depicted person on request to [email protected].

4. What we process, for how long, and why

The subject matter, duration, nature and purpose of the processing, and the categories of personal data and data subjects, are in Annex 1, which satisfies Article 28(3) of the GDPR, Annex I of the SCCs and Article 34(2) of the GAID 2025. Processing lasts as long as your account is open, plus the deletion periods in section 14, and is only to provide, secure, support and operate the Service for you.

5. Our obligations as your processor

We comply with Article 28(3) of the GDPR.

(a) We process Customer Personal Data only on your documented instructions, being the Terms, this Addendum, your configuration, and the tasks you give Varren through the interface, the API or an agent mandate. Where a law we are subject to requires another purpose, we inform you first, unless that law prohibits it on important grounds of public interest.

(b) Confidentiality. Everyone we authorise is bound by a written confidentiality obligation surviving their engagement, is trained on data protection before access, and holds need-to-know access removed when the need ends.

(c) Security. We maintain the measures in Annex 2, taking account of the state of the art, cost, the nature and purposes of processing, and the risks to people. We may change a measure but not so as to materially reduce overall security.

(d) Sub-processors: section 7.

(e) Data subject requests: section 11.

(f) Assistance with security, breach notification, impact assessments and prior consultation: sections 9, 10 and 12.

(g) Deletion or return: section 14.

(h) Information and audit: section 13.

We inform you if an instruction appears to us to infringe Data Protection Law, and we may pause that processing until it is resolved.

6. Your obligations as controller

You confirm that you have a valid lawful basis for the personal data you put into Varren and for what you ask Varren to do with it; that you have given the people concerned the information the law requires; that your instructions will not put us in breach; and that you hold every consent and authority needed for the accounts you connect and the people you contact. You are responsible for the accuracy of what you upload and for configuring the approval and retention controls the Service provides.

We do not monitor what you put into the Service, and we have no obligation to monitor, review, screen or moderate Customer Personal Data. The closing paragraph of section 5 requires us to raise an instruction that appears to us to infringe Data Protection Law; it does not make us a reviewer of what you upload or of what you ask Varren to do, and nothing we fail to notice shifts your responsibility as controller onto us.

Indemnity. You will indemnify us against third-party claims, regulatory fines and reasonable costs, including reasonable legal costs, arising from an instruction that breached Data Protection Law or from personal data you supplied without a lawful basis. We will notify you promptly of any claim, will not settle it without your agreement, and will let you control the defence. This indemnity does not cover anything caused by our own breach of this Addendum. Where you are a consumer, this indemnity applies only to the extent the consumer law of your country of residence permits, and clause 23 of the Terms applies to it.

7. Sub-processors

You give us a general written authorisation to engage sub-processors. This section is that authorisation for Articles 28(2) and 28(4) of the GDPR and for clause 9(a), option 2, of the SCCs.

We use sub-processors for infrastructure, storage, delivery, payments, connectors, browser infrastructure, web search and the AI model providers our routing layer calls. Routing is provider-agnostic, so the provider set changes as models change.

The current list is published at https://varren.co/subprocessors. That page, as amended from time to time under this section, is Annex 3 to this Addendum and Annex III of the SCCs, and Annex 3 below is a pointer to it rather than a separate copy. It names, for each sub-processor, the company, its role, the categories of data it handles, the regions it processes in, and the transfer mechanism. A prior version of that page is available from the company on request to [email protected].

Notice and objection. Before adding or replacing a sub-processor we give at least thirty (30) days notice, that being the period specified for clause 9(a) of the SCCs. Notice is given by email to the data protection or billing contact on your account and in the Service, and the amended sub-processor page is published. Within those thirty days you may object in writing to [email protected] on reasonable data protection grounds, and we will work with you on an alternative. Model routing is a single service-wide configuration; for a model provider the alternative is removal of that provider from the routing configuration for all customers rather than exclusion for your workspace alone. If no alternative exists you may terminate the affected part of the Service, or the Service as a whole if the affected part is essential to your use of it, on written notice, and we will refund prepaid fees for the unused remainder of your term together with the value of your unspent unexpired Credits, calculated as in clause 15.3 of the Terms. This refund right is an exception to clause 16.3 of the Terms and prevails over it. We act on shorter notice only where genuinely needed to keep the Service secure or operational, and inform you at once.

Every sub-processor we appoint is bound by written terms no less protective than these, and we remain fully liable to you for a sub-processor's performance as for our own.

8. International transfers

The United Arab Emirates has no adequacy decision from the European Commission. Ajman Free Zone has no data protection law of its own, so the UAE federal regime applies and no free zone equivalence finding is available. Every transfer to us from the European Economic Area, the United Kingdom or Switzerland is a restricted transfer requiring a mechanism.

8.1 EU Standard Contractual Clauses

The SCCs are incorporated by reference and form part of this Addendum, as follows.

8.2 United Kingdom

For transfers subject to the UK GDPR the UK Addendum applies to the SCCs above and is incorporated by reference: Table 1 is the party detail in Annex 1; Table 2 is module two or three as determined above, with the elective clauses as selected above; Table 3 is Annexes 1, 2 and 3; and Table 4 selects the Importer as the party who may end it, that right arising only if the Information Commissioner revises the Approved Addendum so as to substantially increase our cost or risk, in which case we would put an alternative mechanism in place. References to the GDPR read as the UK GDPR, the supervisory authority is the Information Commissioner, and the governing law and courts are those of England and Wales.

8.3 Switzerland

For transfers subject to the Swiss Federal Act on Data Protection the SCCs apply with the following amendments. The supervisory authority is the Federal Data Protection and Information Commissioner. References to the GDPR read as references to that Act. "Member State" is not read so as to prevent a Swiss data subject suing where they habitually reside. The protection covers natural persons, the revised Act no longer covering legal entities.

8.4 Nigeria and Kenya

For transfers out of Nigeria we rely on Part VIII of the Nigeria Data Protection Act 2023 and, absent an adequacy decision by the Commission, on this Addendum with the SCCs as a cross-border data transfer instrument of the kind contemplated by Schedule 5 to the GAID 2025.

Which entity is your processor when an affiliate invoices you. Where an Affiliate as defined in clause 3.1 of the Terms invoices you locally, including our Nigerian affiliate under clause 3.2, that Affiliate acts only as our billing agent and does not become the processor of Customer Personal Data. Alpha Innovation Technologies - F.Z.C remains your processor and the data importer under this Addendum, and remains solely responsible to you. Where an Affiliate processes Customer Personal Data, it does so as our sub-processor under section 7, bound by written terms no less protective than this Addendum, and we remain fully liable to you for what it does. No affiliate holds a data protection contact point or a local statutory address for us in Nigeria or elsewhere. Every data protection matter reaches Alpha Innovation Technologies - F.Z.C at [email protected]. Our registration position in Nigeria is at https://varren.co/representatives.

For transfers out of Kenya we rely on section 48 of the Kenya Data Protection Act 2019 and the safeguards evidenced by this Addendum, the SCCs and Annex 2. Where you direct us to process sensitive personal data of Kenyan data subjects outside Kenya, the consent that the Act requires for that transfer is yours to obtain.

8.5 Onward transfers and government demands

We make no onward transfer except to a sub-processor under section 7, on the same terms.

We disclose Customer Personal Data to a government authority only under a valid, binding legal order that applies to us. We check every request for validity and scope, challenge overbroad ones, disclose the minimum required, notify you unless legally prohibited, and wherever lawful direct the requester to you instead.

We maintain a transfer impact assessment covering United Arab Emirates law and the jurisdictions of our sub-processors. We review it at least annually and whenever a sub-processor or a routing jurisdiction changes, and we send the current version to you within ten business days of a request to [email protected].

9. Security, tenant isolation and the learning boundary

We maintain the measures in Annex 2. Two of them are contractual promises.

Tenant isolation is absolute. Your data is scoped to your tenant at the database layer by default and does not reach another customer's workspace: not in output, not in a suggestion, not in a retrieved snippet, not in a prompt sent to a model.

Cross-customer learning never includes your personal data. What may generalise across customers is patterns, structures, quality signals such as whether an output was accepted or rejected, and aggregate measures from which no person, record or customer can be identified. What never leaves your tenant is your content, the identity of anyone in your data, your numbers, your documents, your connected accounts and your workspace configuration. Customer Personal Data is never an input to cross-customer learning, and we never use it to train or improve a general-purpose or foundation model of our own. We require the same of every model provider we route to in the terms of the tier we use, as section 18 sets out. On request to [email protected] we exclude your workspace from the pattern layer with no loss of function to you.

Google Workspace data is handled separately and more strictly. Data we obtain through a Google Workspace API, including Gmail, Google Drive and Google Calendar, is used only to provide and improve the user-facing features you asked for. It is never an input to cross-customer learning, we never use it to develop, improve or train any machine learning or artificial intelligence model, generalised or otherwise, and it is never transferred to a third party except as necessary to provide those features to you, for security purposes, or to comply with applicable law. No human at Varren reads it except with your affirmative consent, for a security purpose, or where the law requires it. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy. Where a feature you asked for needs a model, the extract goes through the same service-wide routing configuration as every other request; the training and retention requirement in section 18 applies to that call, and on request to [email protected] we remove a named provider from the routing configuration for all customers. Where we find that a provider's terms are inconsistent with the Google API Services User Data Policy, including the Limited Use requirements, we remove that provider from the routing configuration for all customers.

Enforcement. Every store of customer data is registered as tenant-scoped, cross-tenant paths are covered by automated tests that fail the build if tenant data crosses the boundary, and endpoints touching global state sit on an owner-only list with its own test.

10. Personal data breach

Where we confirm a personal data breach affecting Customer Personal Data we notify you without undue delay and within forty-eight (48) hours of that confirmation. The forty-eight hours runs from the point at which we have established, to a reasonable degree of certainty, that a breach has occurred, and not from the first sign of an event still under investigation. That period reflects the notification deadline Kenyan law places on a data processor and leaves you time for your own 72 hours under Article 33 of the GDPR and under the Nigeria Data Protection Act 2023.

An unsuccessful attempt is not a personal data breach for this purpose: failed log-in attempts, pings, port scans, denial of service attempts, and other attacks on firewalls or network equipment that do not compromise Customer Personal Data are excluded. An incident caused by the loss, sharing or compromise of your own credentials, access tokens or connected-account sessions, other than through our fault, is your breach and not ours, and we will assist you in handling it.

Our notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, what we have done or propose to do, and a contact point. Where we do not have all of it at once we send what we have and follow up. We cooperate with your investigation and notifications, and will not notify a regulator or a data subject on your behalf unless you ask us to or the law requires it. A notification is not an admission of fault.

11. Data subject requests

You can find, correct and delete personal data inside your workspace, so in most cases you can answer a request without us. There is no self-service export in the Service. To obtain a copy of personal data held in your workspace, write to [email protected] and a person produces it for you, at no charge, within thirty (30) days. Where a data subject contacts us directly about Customer Personal Data we do not answer substantively: we direct them to you and forward the request within three (3) business days unless the law prevents it.

Where those tools are not enough we assist you with appropriate technical and organisational measures, insofar as possible and taking account of the nature of the processing and the information available to us, so you can answer requests for access, rectification, erasure, restriction, portability, objection and automated decision-making. Reasonable assistance is at no charge. Where a request or a pattern of requests is manifestly excessive, repetitive, or requires engineering work beyond what this section ordinarily involves, we may charge our reasonable costs at our then-current professional services rate; we provide the estimate in writing and obtain your agreement before we start, and we never withhold assistance the law requires because of a fee dispute.

12. Impact assessments and prior consultation

Taking account of the nature of the processing and the information available to us, we assist you with data protection impact assessments and prior consultation of a supervisory authority under Articles 35 and 36 of the GDPR and the equivalent provisions of the Kenya Data Protection Act 2019 and the Nigeria Data Protection Act 2023. That assistance comprises a current description of the processing, Annex 2, the sub-processor page, the transfer impact assessment, and a written account of how the approval spine and the audit trail work. Assistance beyond that, such as bespoke assessment drafting for your organisation, is chargeable on the basis in section 11.

13. Audit and information rights

On request and at no charge we provide this Addendum and its annexes, with Annex 2 as our security documentation, the sub-processor page as our sub-processor list, the transfer impact assessment, and any third-party audit report or certification we hold. Where you send us your own security questionnaire we complete and return it within ten business days.

Where that is not enough to verify our compliance with Article 28, you may audit us on the following conditions:

An audit gives no access to another customer's data, to our commercially sensitive information, or to anything that would put the security of the Service at risk. Penetration testing and anything touching production require our written agreement on scope and timing first. You bear your own and your auditor's costs, and we may charge reasonable costs for our people's time beyond the first working day. You may audit more often and at shorter notice where a supervisory authority requires it or after a confirmed breach affecting your data. This section is how clause 8.9 of the SCCs is performed.

14. Deletion and return

Export. There is no self-service export in the Service. You may request a copy of Customer Personal Data at any time while your account is open and for thirty (30) days after it closes, by writing to [email protected], and we produce it within 30 days of your request at no charge, in structured, commonly used, machine-readable formats: your records as JSON or CSV, and your uploaded and generated files in the format they were stored in. This discharges our obligation to return Customer Personal Data under Article 28(3)(g). A bespoke migration in another format is quoted for as professional services.

Deletion. At the end of that window we delete Customer Personal Data from live systems within a further thirty (30) days. Copies inside database snapshots are deleted when the snapshot holding them is deleted. We retain the most recent snapshots, currently the newest seven, deleting older ones as new ones are written. Snapshots are compressed rather than separately encrypted and are used only to restore the Service. Where a restore reinstates data you asked us to delete, we delete it again and inform you. We keep data longer only where a law requires it, where you have instructed us to retain it, or where it is subject to a litigation hold, preservation order or regulatory demand that applies to either party, for only as long as that requires, isolated and still protected by this Addendum. Where a hold is the reason, we inform you as soon as we lawfully can and delete the data when the hold lifts. On written request we certify the deletion.

The audit trail, which you instruct us to keep. You instruct us to retain the tamper-evident audit trail for six years after the action, as the evidence that Varren did only what it was instructed to do. Personal data in the trail is limited to what identifies the actor and the action: no message bodies, no uploaded documents, no generated media. You may instruct us to shorten this period or to delete the trail on account closure, by writing to [email protected], and we will do so.

15. Liability

Each party's total aggregate liability arising out of or in connection with this Addendum, in contract, in tort including negligence, for breach of statutory duty or otherwise, is subject to and counts towards the limitation of liability in clause 18 of the Terms. This Addendum creates no separate cap and no additional pot of liability.

A breach of section 9 of this Addendum is a breach of the tenant isolation and confidentiality obligations in clauses 10.4 and 22.1 of the Terms, and clause 18.3 gives those claims a higher cap than anything else in the contract: the greater of twice your last twelve months of fees or USD 25,000.

Four things sit outside it:

  1. Liability to a data subject under clause 12 of the SCCs, and any other liability to a data subject that cannot be limited by contract.
  2. An administrative fine imposed by a regulator directly on one party, which is borne by that party.
  3. Your indemnity in section 6.
  4. Any liability that cannot be limited by law, including for fraud.

Where both parties are responsible for the same damage, each bears the share reflecting its own responsibility.

16. Special categories, likeness and biometric data

Varren does not require special categories of personal data and you should not upload them unless a feature you use requires them. Where you upload a reference photograph, video or voice recording of a real person so Varren can generate media preserving that likeness, we treat the reference and everything derived from it as special category biometric data, whether or not it crosses the Article 9 threshold, and process it only as your processor.

You are its controller and the consent is yours to hold. You must have explicit consent from the person depicted under Article 9(2)(a) of the GDPR or its local equivalent before you upload, and you must record who they are and the basis on which you hold their permission and produce it to us on request. A reference you attach is sent with the generation request to the model provider named in Annex 3 and is not retained by us once the request completes. Where we hold reference material or a derived representation, it is deleted twelve (12) months after your last generation using it, or immediately on deletion or withdrawal of consent, whichever is first. A depicted person may withdraw consent by writing to [email protected] whether or not they are a Varren customer. The uses prohibited by the Terms, including likenesses of children, sexual imagery of a real person and synthetic media of election candidates, cannot be instructed here.

We make the following commitments directly, because some biometric privacy statutes, including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act and the Washington My Health My Data Act, place duties on any private entity that obtains a biometric identifier whatever its role under data protection law:

  1. We do not sell, lease, trade or otherwise profit from any biometric identifier or biometric information we hold, and we do not disclose it except to a sub-processor under section 7 to perform the generation you asked for, where the law requires it, or where you instruct us.
  2. This section, with the retention periods in it, is our publicly available written policy establishing a retention schedule and guidelines for the permanent destruction of biometric identifiers and biometric information, and we destroy the material when the purpose of collection has been satisfied or within the periods stated here, whichever is first.
  3. We store, transmit and protect biometric material using the reasonable standard of care in our industry, in a manner at least as protective as that in which we store, transmit and protect other confidential and sensitive information.

17. Autonomous action and automated decisions

Varren acts on your behalf on connected platforms under a mandate you grant and can withdraw. Those are your actions, and the personal data processed in carrying them out is Customer Personal Data processed on your instructions. Where you configure Varren so that a decision about a person is made without meaningful human involvement and produces legal or similarly significant effects on them, you are the controller of that processing and Article 22 of the GDPR falls on you. We provide the approval spine and the audit trail so that meaningful involvement is possible. There is no single control that halts all activity at once; the human involvement must be the approvals you keep in place before an action runs.

18. Artificial intelligence model providers

To generate content we send prompts and the material they require to third-party model providers, which are sub-processors under section 7 and are named in Annex 3.

Google Workspace carve-out. Nothing above permits any use of Google Workspace data inconsistent with section 9. The requirement we place on every provider we route to applies to data obtained through a Google Workspace API. Routing is a single service-wide configuration, so Google Workspace data reaches the same provider set as every other request; where a provider's terms are inconsistent with the Google API Services User Data Policy, including the Limited Use requirements, we remove that provider from the routing configuration for all customers.

19. United States state privacy laws

Where you are a business or controller subject to the CCPA, or to the comprehensive privacy law of Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, Tennessee or Utah, we are your service provider or processor and not a third party. The following terms apply.

  1. No sale and no share. We will not sell or share your personal information as those terms are defined in those laws, and we receive no consideration for it. Our fees are consideration for the Service, not for the personal information.
  2. Limited purpose. We process personal information only to perform the Service under this Addendum and for no other commercial purpose, and we do not retain, use or disclose it for any purpose other than the business purposes specified in Annex 1, or outside our direct business relationship with you.
  3. No combining. We will not combine your personal information with personal information we receive from any other source, except as those laws expressly permit a service provider to do.
  4. Same level of protection. We comply with the obligations those laws place on a service provider or processor and give the personal information the same level of privacy protection those laws require of you.
  5. Your right to check us. You may take reasonable and appropriate steps to confirm that we use your personal information consistently with your obligations, and to stop and remediate any unauthorised use. Section 13 is how that right is exercised.
  6. Notice if we cannot comply. Where we determine that we can no longer meet these obligations, we will inform you at [email protected] without undue delay, and you may take the steps those laws allow.
  7. Sub-processors. Where we engage a sub-processor under section 7 that processes personal information subject to these laws, we do so under a written contract imposing these same obligations on it.
  8. Deidentified data. Where we hold deidentified data, we maintain it in deidentified form, take reasonable measures to prevent reidentification, publicly commit not to attempt to reidentify it except to test that the deidentification holds, and contractually bind anyone who receives it to the same.

Personal information we receive from you under this Addendum is disclosed for the limited and specified business purposes in Annex 1. Nothing in this section makes us a controller or business in respect of Customer Personal Data.

20. Records and data protection contact

We keep the records of processing carried out on your behalf that Article 30(2) of the GDPR requires. Annex 1 is the substance of those records, and we send you a copy in the form Article 30(2) sets out within ten business days of a request to [email protected].

Our data protection contact is [email protected], and legal notices go to [email protected].

We are established in the United Arab Emirates. Where Article 27 of the GDPR or of the UK GDPR requires us to designate a representative in the Union or the United Kingdom, we make that designation and give you the representative's name and address within ten business days of a request to [email protected]. Our current registration position in every country, including Nigeria and Kenya, is published and kept current at https://varren.co/representatives. We hold no local statutory address and no local contact point in any country; every data protection matter reaches Alpha Innovation Technologies - F.Z.C at [email protected].

21. General

Changes. We may update this Addendum for a change in law, in the Service or in a transfer mechanism. For a change materially affecting your rights we give at least 30 days notice by email and in the Service. Prior versions are available from the company on request to [email protected] within five business days. Within those 30 days you may object in writing to [email protected], and where we cannot resolve your objection you may terminate the affected part of the Service before the change takes effect, and we will refund prepaid fees for the unused remainder of your term together with the value of your unspent unexpired Credits. We will not make a change that reduces the protection this Addendum gives to Customer Personal Data below what Data Protection Law requires, and we will not amend the Standard Contractual Clauses. Adding a sub-processor is handled under section 7 and is not a change to this Addendum.

Governing law and forum. Except where the SCCs or the UK Addendum provide otherwise, this Addendum is governed by the laws of the Dubai International Financial Centre and the DIFC Courts have exclusive jurisdiction, in line with the Terms.

Severability and term. Any part held invalid is narrowed to the smallest extent that makes it enforceable, or removed if it cannot be saved, and the rest continues. This Addendum takes effect when you accept the Terms and continues while we process Customer Personal Data. Sections 9, 10, 13, 14, 15, 16 and 19 survive it.


Annex 1: Details of the processing

This Annex is Annex I.A, I.B and I.C of the SCCs, Tables 1 and 3 of the UK Addendum, and the description required by Article 28(3) of the GDPR and Article 34(2) of the GAID 2025.

Data exporter, controller (or processor where section 3 applies). You: the entity or person that accepted the Terms, identified by the legal name, registered address, billing contact and contact email recorded in your Varren account, which form part of this Annex. Activities: use of the Service to create content and act on connected accounts.

Data importer, processor (or sub-processor). Alpha Innovation Technologies - F.Z.C, trading as AlphaIT Engineering, Ajman Free Zone Authority Building, Sheikh Rashid Bin Saeed Al Maktoum Street, Ajman Free Zone, PO Box 932, Ajman, United Arab Emirates. Contact: [email protected]. Activities: hosting and operating the Varren Service.

Signature and date. Acceptance of the Terms, on the date and time in the acceptance record kept under clause 6.3 of the Terms.

Categories of data subjects. Your personnel and authorised users; your clients, customers, leads and prospects; correspondents in mailboxes and messaging accounts you connect; recipients and audiences of what you send or publish; people named, described or depicted in material you upload; and people whose likeness or voice you upload with their consent.

Categories of personal data. Names and contact details; professional and employment details; account, login and authentication data; the content of communications you send, receive or draft through the Service; documents, brand assets, images, audio, video and other uploaded material; connected account identifiers, scopes and access tokens; instructions, prompts and generated outputs containing personal data; usage, approval and audit records; and commercial data such as pipeline and campaign information.

Special categories. Only where you choose to provide them, which in practice means biometric likeness data: reference photographs, video and voice recordings of a real person and representations derived from them, handled under section 16. Any other special category data reaches us only because you place it there.

Frequency. Continuous, while your account is open. Duration. The term of your account plus the deletion periods in section 14. Sub-processors: as in section 7 and Annex 3, for the duration of their engagement.

Nature and purpose, and the business purposes for section 19. Hosting, storage, retrieval, organisation, generation of content using artificial intelligence models, execution of actions you have mandated on connected platforms, sending email and messages at your direction, web search carried out for a research task you asked for, indexing within your tenant, security monitoring, fraud prevention, support, billing, and maintaining the audit trail, solely to provide the Service to you. These are the limited and specified business purposes for which personal information is disclosed to us under section 19.

Competent supervisory authority (Annex I.C). Where you are established in the European Economic Area, the supervisory authority of your Member State of establishment. Where you are not established in the European Economic Area but fall within Article 3(2) of the GDPR and have appointed a representative under Article 27, the supervisory authority of the Member State where that representative is established. In every other case, and as the default recorded in this Annex, the Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. For UK transfers, the Information Commissioner. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Mapping to Article 34(2) of the GAID 2025. Parties and addresses: above. Recitals and principal agreement: section 1. Purpose, scope, nature and lawful bases: above and section 6. Location of processing and cross-border grounds: section 8 and Annex 3. Responsibilities: sections 5 and 6. Technical and organisational measures: Annex 2. Impact assessment outcome and potential risks: section 12. NDP Act compliance and registration: section 20. Confidentiality: section 5(b). Tenure: section 21. Specific restrictions: sections 5(a), 9 and 16. Indemnity: sections 6 and 15. Force majeure and dispute resolution: the Terms.


Annex 2: Technical and organisational measures

This Annex is Annex II of the SCCs.

Encryption. Traffic is encrypted in transit with TLS. Secrets we hold, including connected-account tokens and stored session material, are encrypted at rest using authenticated encryption that fails closed on tampering or on a wrong key, so a corrupted or substituted value is rejected rather than silently accepted. Keys sit outside the database, are never logged and are never returned through the interface or the API.

Access control. Role-based, with ranked roles, per-role and per-user permissions, and a guard preventing a lower role from altering a higher one. Two-factor authentication using time-based one-time passwords under RFC 6238, with recovery codes stored only as hashes, is available and can be required by role. Operator endpoints sit behind an owner-only prefix list enforced in code and covered by its own automated test.

Integrity. Workspace activity, including published and scheduled actions, is written to an append-only, hash-chained audit trail in which each event carries the hash of the one before it, so a deletion or alteration is detectable, and the chain can be verified on demand. The trail is tenant-scoped. Autonomous actions pass through an approval spine recording who approved what and when, in which an approval is matched to the exact action at the moment of execution, is single use, and expires. The approval spine keeps its own append-only record, which has no update or delete path anywhere in the Service. There is no control that halts all activity at once; approvals are withdrawn and connected accounts disconnected.

Availability. Managed cloud infrastructure behind a content delivery and edge protection layer. Database backups use an online, transactionally consistent mechanism. Every snapshot is integrity-checked as it is written, and one that fails the check is deleted rather than kept. We retain the most recent snapshots rather than a fixed period. Restores are tested.

Isolation of customer data. Multi-tenancy is enforced at the data layer. Every table holding customer data is registered as tenant-scoped and the registration is verified by an automated test; deliberately global tables are listed separately so that nothing becomes global by accident. Retrieval feeding a model prompt is scoped to the requesting tenant. Cross-tenant leakage is covered by dedicated fail-closed tests, and a failure breaks the build.

Testing. The full automated suite, including tenant isolation, endpoint authorisation, security boundary and research isolation tests, runs before release, and security-relevant changes are reviewed independently of whoever made them.

Minimisation. We send a model provider only what the task requires. You control what is uploaded, retained and deleted.

Personnel. Written confidentiality obligations surviving engagement, data protection training, and need-to-know access removed when the need ends.

Sub-processor governance. Written terms no less protective than this Addendum, a named list on the sub-processor page, and the 30 day notice and objection mechanism in section 7.

Incident response. Alerting on the signals that indicate an incident, then containment, assessment, notification under section 10, and a post-incident review. Report a suspected incident to [email protected], marked urgent.

Transfer measures. Encryption in transit for all traffic, encryption at rest for connected-account tokens, stored session material and other secrets, tenant-scoped access control, minimisation of what is sent onward, a published position on government access, and a transfer impact assessment reviewed at least annually and available on request.


Annex 3: Sub-processors

The current sub-processor list is published and versioned at https://varren.co/subprocessors. That page, as amended from time to time under section 7, is Annex 3 to this Addendum and Annex III of the SCCs, and it is incorporated into this Addendum by reference. This Addendum carries no separate copy of the list.

For each sub-processor, that page names the company, its role, the categories of data it handles, the regions it processes in, and the transfer mechanism relied on. It names any recipient that processes data without a contract behind it, and it identifies the two model providers that process in the People's Republic of China, for which there is no European adequacy decision. A prior version of that page is available from the company on request to [email protected].

The authorisation, the 30 day notice mechanism and your right to object are in section 7. The transfer mechanism relied on for each sub-processor, including the Standard Contractual Clauses with the UK Addendum or the Swiss amendments where they apply, or an adequacy decision covering that provider's location, is stated per provider on that page. We remain fully liable to you for what each sub-processor does.

Where an Affiliate as defined in clause 3.1 of the Terms processes Customer Personal Data, it does so as our sub-processor on the terms in section 8.4, and it is treated as listed in this Annex.


Alpha Innovation Technologies - F.Z.C, trading as AlphaIT Engineering. Ajman Free Zone, Ajman, United Arab Emirates. Contact: [email protected]. Read together with the Terms of Service at https://varren.co/terms and the Privacy Policy at https://varren.co/privacy.