Omi STT API — Data Processing Agreement

Version 2.2 — Effective date: 25 August 2026

This Data Processing Agreement ("DPA") forms part of the Omi STT API service terms (the "Agreement") between Omi Health B.V., KVK 69497680, Eindhoven, the Netherlands ("Omi") and the customer accepting the Agreement ("Customer"). It is built on the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/915 and applies whenever Omi processes personal data on Customer's behalf within the scope of Article 28 GDPR. It is concluded in electronic form in accordance with Article 28(9) GDPR.

Section I — General

Clause 1 — Purpose and scope

(a) The purpose of this DPA is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 (GDPR).

(b) Customer acts as controller and Omi acts as processor of the Customer Personal Data described in Annex I.B. Where Customer itself acts as a processor for a third-party controller, Customer is Omi's instructing party, Omi is engaged as a sub-processor, and references to "controller" in this DPA are read as references to Customer acting on the documented instructions and with the authorisation of its controller. Customer warrants that its instructions to Omi are authorised by that controller and that its own contract with that controller permits Omi's engagement on these terms.

(c) This DPA applies to the processing of Customer Personal Data as specified in Annex I.

(d) Annexes I to III are an integral part of this DPA.

(e) This DPA is without prejudice to obligations to which Customer is subject under the GDPR.

(f) "Customer Personal Data" means personal data in Customer Content processed by Omi on Customer's behalf. "Customer Content" means Job Content (submitted audio, job-scoped custom vocabulary and job options, and the transcripts and results generated from them) and persistent custom vocabulary saved to Customer's account. Account, usage, and billing data that Omi processes for its own purposes ("Service Data") is processed by Omi as an independent controller under its Privacy Notice and is outside this DPA.

Clause numbering follows the 2021/915 model clauses. The model's Clause 2 (invariability) and optional Clause 5 (docking) apply to the executed standard clauses themselves and are not reproduced here.

Clause 3 — Interpretation

Terms defined in the GDPR have the same meaning in this DPA. This DPA shall be read and interpreted in the light of the GDPR and shall not be interpreted in a way that runs counter to rights and obligations provided for in the GDPR or that prejudices the fundamental rights or freedoms of the data subjects.

Clause 4 — Hierarchy

In the event of a contradiction between this DPA and the provisions of the Agreement or any other agreement between the parties, this DPA prevails for the processing of Customer Personal Data. Where the parties have separately executed the standard contractual clauses of Commission Implementing Decision (EU) 2021/915, those clauses prevail over this DPA.

Section II — Obligations of the parties

Clause 6 — Description of processing

The details of the processing, in particular the categories of personal data and the purposes for which it is processed on Customer's behalf, are specified in Annex I. The rights and obligations of Customer as controller are set out in this DPA, in particular in Clauses 7.1, 7.6, 7.7, 8, 9, and 10.

Clause 7 — Obligations of the parties

7.1 Instructions

(a) Omi shall process Customer Personal Data only on documented instructions from Customer, unless required to do so by Union or Member State law to which Omi is subject; in that case, Omi shall inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Agreement, this DPA, each API request (including the retention period selected for a job), and configuration made through the console are Customer's documented instructions. Instructions include any authorisation of international transfers under Clause 7.8. Subsequent instructions may be given throughout the processing and shall be documented.

(b) Omi shall immediately inform Customer if, in Omi's opinion, an instruction given by Customer infringes the GDPR or other Union or Member State data protection provisions.

7.2 Purpose limitation

Omi shall process Customer Personal Data only for the purposes set out in Annex I, unless it receives further documented instructions from Customer. Omi does not use Customer Content to train, fine-tune, or evaluate any model; does not sell it; does not use it for marketing; and does not derive anything from it beyond the requested transcript and results.

7.3 Duration of processing and deletion

(a) Processing takes place for the duration specified in Annex I.

(b) Submitted audio is deleted automatically upon completion or terminal failure of processing. Transcripts from synchronous requests are not stored. Results of asynchronous requests are stored solely for retrieval and deleted automatically at the end of the retention period selected by Customer (1 to 72 hours; default 24 hours). Job-scoped custom vocabulary is deleted with the job. Content is never written to operational logs or backups. The retention period selected by Customer is Customer's documented instruction. Retention particulars, including the effective minimum retention for jobs configured with webhook delivery, are stated in the Service documentation and Annex I.

(c) Persistent custom vocabulary saved to Customer's account outside an individual job is account configuration, not Job Content. Its content, storage, and deletion behaviour are described in Annex I. Customer may delete it through the Service at any time, and Omi deletes it on account termination.

7.4 Security of processing

(a) Omi shall implement at least the technical and organisational measures specified in Annex II to ensure the security of Customer Personal Data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access (personal data breach). In assessing the appropriate level of security, the parties take due account of the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks involved for data subjects.

(b) Omi grants its personnel access to Customer Personal Data only to the extent strictly necessary for implementing, managing, and monitoring the Agreement. Omi ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7.5 Sensitive data

The Service is designed to process audio that contains data concerning health and other special categories of personal data (Article 9 GDPR). Omi applies the specific restrictions and additional safeguards identified in Annex II for such data, including strict purpose limitation, the deletion scheme in Clause 7.3, encryption in transit and at rest, role-based access restriction with logging, and audit logs designed to contain no Customer Content.

7.6 Documentation, compliance, and audits

(a) The parties shall be able to demonstrate compliance with this DPA. Omi shall deal promptly and adequately with inquiries from Customer about the processing of Customer Personal Data.

(b) Omi shall make available to Customer all information necessary to demonstrate compliance with the obligations in this DPA and stemming directly from the GDPR, including this DPA, the current sub-processor list, Annex II, deletion (purge-probe) evidence, and third-party audit reports or certifications when available.

(c) At Customer's request, Omi shall permit and contribute to audits of the processing activities covered by this DPA, at reasonable intervals or if there are indications of non-compliance. Customer may conduct the audit itself or mandate an independent auditor; audits may include inspections at Omi's premises or physical facilities and shall, where appropriate, be carried out with reasonable notice. Absent indications of non-compliance, audits occur no more than once per twelve months, on at least thirty (30) days' notice, during business hours, without unreasonable disruption, under confidentiality, and at Customer's cost. These limits do not apply where an audit is prompted by a personal data breach affecting Customer Personal Data, a request or investigation by a competent supervisory authority, credible indications of material non-compliance, or a binding legal deadline of Customer; in those cases Omi contributes without the frequency and notice limits, and Omi bears the costs where material non-compliance is found.

(d) The parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority or authorities on request.

7.7 Use of sub-processors

(a) Customer grants Omi general written authorisation to engage sub-processors from the agreed list in Annex III. Omi shall specifically inform Customer in writing of any intended change of that list through the addition or replacement of sub-processors at least thirty (30) days in advance, giving Customer sufficient time to object before the engagement. Omi shall provide the information necessary to enable Customer to exercise its right to object.

(b) If Customer objects on reasonable data-protection grounds, the parties shall discuss the objection in good faith and Omi shall, where reasonably possible, offer an alternative that avoids the objected-to sub-processor. If no reasonable alternative exists, Customer may terminate the affected Service, retrieving its results first in accordance with Clause 10(d).

(c) Where Omi engages a sub-processor to carry out specific processing activities on behalf of Customer, it shall do so by way of a contract that imposes on the sub-processor, in substance, the same data protection obligations as those imposed on Omi under this DPA. Omi shall ensure that the sub-processor complies with the obligations to which Omi is subject under this DPA and the GDPR.

(d) At Customer's request, Omi shall provide a copy of such a sub-processor agreement and subsequent amendments, redacted to the extent necessary to protect business secrets or other confidential information, including personal data.

(e) Omi remains fully responsible to Customer for the performance of each sub-processor's obligations under its contract with Omi, and shall notify Customer of any failure by a sub-processor to fulfil its contractual obligations.

(f) Omi shall agree a third-party beneficiary clause with each sub-processor whereby, in the event Omi has factually disappeared, ceased to exist in law, or become insolvent, Customer has the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data.

7.8 International transfers

(a) Any transfer of Customer Personal Data to a third country or an international organisation by Omi shall take place only on the basis of documented instructions from Customer or to fulfil a specific requirement under Union or Member State law to which Omi is subject, and shall comply with Chapter V GDPR.

(b) Processing of Customer Content takes place in the European Union (AWS eu-central-1, Frankfurt). Customer agrees that, where processing by a sub-processor involves a transfer within the meaning of Chapter V GDPR, Omi and the sub-processor ensure compliance with Chapter V by means of the applicable module of the standard contractual clauses adopted under Article 46(2)(c) GDPR as incorporated in that sub-processor's data processing agreement with Omi — for AWS, the AWS GDPR Data Processing Addendum, which incorporates the SCC modules applicable to the parties' roles — provided the conditions for the use of those clauses are met. Omi documents the transfer assessments for such transfers and makes them available under Clause 7.6.

(c) This Clause remains in effect after the preview transition ends. It governs any non-EEA processing that may arise, including support, remote access, or disaster recovery, for as long as this DPA is in force.

Clause 8 — Assistance to Customer

(a) Omi shall promptly notify Customer of any request it receives from a data subject relating to Customer Personal Data. Omi shall not respond to the request itself, unless authorised to do so by Customer.

(b) Omi shall assist Customer in fulfilling its obligations to respond to data subjects' requests to exercise their rights, taking into account the nature of the processing. Where Customer Content has already been deleted under Clause 7.3, Omi's assistance consists of promptly confirming that fact; nothing in this DPA requires Omi to recreate deleted data.

(c) Omi shall furthermore assist Customer in ensuring compliance with the following obligations, taking into account the nature of the processing and the information available to Omi:

1. the obligation to carry out a data protection impact assessment where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35 GDPR);

2. the obligation to consult the competent supervisory authority prior to processing where a data protection impact assessment indicates a high residual risk (Article 36 GDPR);

3. the obligation to ensure that personal data is accurate and up to date, by informing Customer without delay if Omi becomes aware that personal data it is processing is inaccurate or has become outdated;

4. the obligations in Articles 32 to 34 GDPR.

(d) The measures by which Omi provides this assistance, and its scope and extent, are set out in Annex II.

Clause 9 — Notification of personal data breach

In the event of a personal data breach, Omi shall cooperate with and assist Customer so that Customer can comply with its obligations under Articles 33 and 34 GDPR, taking into account the nature of the processing and the information available to Omi.

(a) In the event of a personal data breach concerning Customer Personal Data processed by Omi, Omi shall notify Customer without undue delay and in any event within 48 hours after having become aware of the breach. The notification shall contain, at least: (1) a description of the nature of the breach, including where possible the categories and approximate number of data subjects and data records concerned; (2) the details of a contact point where more information can be obtained; and (3) the likely consequences of the breach and the measures taken or proposed to address it, including, where appropriate, measures to mitigate its possible adverse effects.

(b) Where, and insofar as, it is not possible to provide all of this information at the same time, the initial notification shall contain the information then available, and further information shall be provided subsequently without undue delay as it becomes available.

(c) Omi shall assist Customer in notifying the breach to the competent supervisory authority and, where required, in communicating it to affected data subjects, and in obtaining the information that Article 33(3) GDPR requires the controller's notification to state.

Section III — Final provisions

Clause 10 — Non-compliance, termination, and deletion or return

(a) Without prejudice to the GDPR, if Omi is in breach of its obligations under this DPA, Customer may instruct Omi to suspend the processing of Customer Personal Data until Omi complies with this DPA or the Agreement is terminated. Omi shall promptly inform Customer if it is unable to comply with this DPA, for whatever reason.

(b) Customer is entitled to terminate the Agreement insofar as it concerns processing under this DPA where: (1) processing was suspended under point (a) and compliance is not restored within a reasonable time and in any event within one month of suspension; (2) Omi is in substantial or persistent breach of this DPA or its GDPR obligations; or (3) Omi fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under this DPA or the GDPR.

(c) Omi is entitled to terminate the Agreement insofar as it concerns processing under this DPA where, after informing Customer that an instruction infringes applicable legal requirements under Clause 7.1(b), Customer insists on compliance with that instruction.

(d) At the end of the provision of the Services, Omi shall, at Customer's choice, delete all Customer Personal Data processed on Customer's behalf and certify that it has done so, or return it and delete existing copies, unless Union or Member State law requires storage. Retrieval of results through the API before termination constitutes return of Job Content; any remaining Customer Content is deleted by the standing mechanics of Clause 7.3, and persistent custom vocabulary is deleted on account termination. Written confirmation of deletion is available on request. Until deletion or return is complete, Omi continues to ensure compliance with this DPA.

Clause 11 — Governing law

This DPA is governed by the law of the Netherlands, as provided in the Agreement, without prejudice to mandatory provisions of the GDPR.


Annex I — List of parties and description of processing

A. List of parties

Controller / instructing party (Customer): the legal entity accepting the Agreement, as recorded at acceptance (legal name, registered address, contact person, and, where designated, data protection officer). Where Customer acts as processor for a third-party controller, Clause 1(b) applies.

Processor: Omi Health B.V., KVK 69497680, Eindhoven, the Netherlands. Privacy contact: as published at /legal (privacy contact address).

B. Description of processing

Subject matter and nature. Automated conversion of speech to text: receipt of audio submitted through the API, transcription (including optional speaker diarization, formatting, and application of custom vocabulary), and delivery of transcripts and results. Transcription runs on Omi-operated infrastructure; no third-party model APIs are in the inference path.

Purpose. Solely to provide, secure, and support the Service for Customer.

Categories of data subjects. Speakers in submitted audio, including patients, healthcare professionals, and other individuals whose speech or personal details are captured in a recording; individuals mentioned in audio or vocabulary entries.

Categories of personal data.

Special categories of data. Data concerning health (Article 9 GDPR) is expected in submitted audio, transcripts, and vocabulary; the Service is designed for it. Safeguards: Clause 7.5 and Annex II.

Duration of processing.

Annex II — Technical and organisational measures

Concrete measures implemented by Omi for the EU production environment (AWS account region eu-central-1, Frankfurt). Omi may update these measures provided the level of protection is not reduced.

Encryption in transit. TLS for all external API, console, and webhook traffic; internal service traffic within a private VPC.

Encryption at rest. AWS KMS keys managed by Omi (AWS "customer managed keys"), with automatic rotation, for all content-bearing stores: S3 (SSE-KMS with bucket keys), DynamoDB tables, SQS queues, EBS volumes, and CloudWatch log groups. A dedicated audit CMK protects audit storage.

Access control and least privilege. Role-based access control; least-privilege IAM policies; no standing human access to Customer Content; human access only for security or abuse investigation, logged. Administrative access to hosts via AWS Systems Manager (no public SSH); administrative command output is kept content-free.

Authentication and key management. Customer API keys are stored as SHA-256 hashes only; the plaintext key is shown once at creation and cannot be retrieved by Omi staff. Secrets are held in AWS Secrets Manager. Customer identity for the console is managed in an Omi-operated Keycloak instance (identity data only; no Customer Content).

Audit logging. Immutable, content-free audit trail: security and compliance events are delivered to an S3 bucket with Object Lock in COMPLIANCE mode (2,192-day retention); CloudTrail with log-file validation. The audit schema is designed to contain no audio, transcript, filename, or URL content. Periodic log sweeps verify that operational logs contain no Customer Content.

Tenant isolation. Per-customer API keys scope every request; jobs, results, and vocabulary are partitioned per account; authorisation is enforced on every retrieval.

Data minimisation and retention. The retention scheme of Clause 7.3: automatic deletion of audio on completion or terminal failure; no storage of synchronous transcripts; Customer-selected retention (1-72 hours, default 24 hours) for asynchronous results, enforced by an application reaper with an independent storage-lifecycle backstop that removes any residual object no later than fourteen (14) days after creation; job queues and dead-letter queues capped at 72 hours; operational logs retained 3 days; content-free usage metadata 90 days; no backup tier is configured for the Customer Content store, and Customer Content is not written to operational logs or backups. Automated probes and deletion-service metrics continuously verify the deletion scheme and produce exportable evidence.

EU processing. Customer Content is processed in eu-central-1 (Frankfurt) in steady state; any non-EEA processing is governed by Clause 7.8. Identity data for the console is hosted, alongside the Service, on AWS in eu-central-1 (Frankfurt); website static assets are served via CDN; neither path carries Customer Content. The API hostname is DNS-only and API traffic does not transit the website CDN.

Availability and resilience. Multi-AZ load balancing for the API; encrypted managed database with automated backups (identity/account data only, 7-day retention); infrastructure as code with drift monitoring; queue-based retry semantics for asynchronous work.

Personnel. Confidentiality undertakings for all persons authorised to process personal data; written workforce training and sanctions program.

Assistance measures (Clauses 8 and 9). Named privacy contact; breach intake and escalation runbook with templates for Article 33(3) content; console and API access for Customer self-service retrieval and deletion; deletion confirmations on request; sub-processor list with change notification.

Testing and evaluation. Automated probes and deletion-service metrics continuously verify the deletion scheme and produce exportable evidence; periodic log and temp/spool sweeps; conformance runs with evidence packs stored in the immutable audit bucket.

Annex III — Sub-processors

Customer authorises the following sub-processors (Clause 7.7(a)). The live list, with the change-notification mechanism (at least 30 days' advance notice), is published at /legal/sub-processors.

1. Amazon Web Services EMEA SARL (Luxembourg) — cloud infrastructure hosting and processing of Customer Content. Location: eu-central-1 (Frankfurt).

2. Amazon Web Services EMEA SARL — Amazon SES (eu-central-1, Frankfurt) — transactional email delivery for account and billing email. Processes recipient email address and message metadata only. Never processes audio, transcripts, or PHI. (The Omi-operated Keycloak identity service is hosted on AWS under item 1; Microsoft Azure is no longer a sub-processor.)

3. Cloudflare, Inc. — website content delivery network and Turnstile bot protection for the public website and console assets. The API hostname is DNS-only: API traffic, including all Customer Content, does not transit Cloudflare.

4. Stripe (Stripe Payments Europe, Ltd.) — billing and payment processing for the Service. Processes billing contact and transaction data; card data is collected directly by Stripe and never touches Omi systems. Never processes Customer Content.