Data Processing Addendum

Data Processing Addendum

This addendum applies where Ankora is exposed to personal data for which the client is responsible, for example data about the client's employees, customers or suppliers. It is a standing annex to the engagement agreement, and it is designed to let the client meet its own obligations under regulation 15 of the Israeli Privacy Protection (Data Security) Regulations, and under the GDPR for those to whom it applies.

01

1. Status of the parties

The client is the owner of the database and the party that determines the purposes of the processing. Ankora is the holder of the database and processes the data on the client's behalf.

Ankora processes personal data only on the client's documented instructions and for the purpose of providing the service. What constitutes an instruction and a written authorization is defined in the Service Terms, section 3.

If Ankora believes that an instruction from the client conflicts with applicable law, it will say so and will not carry it out until the matter is clarified.

02

2. Categories of data and purpose of processing

The sole purpose of the processing is providing the service. Ankora does not process the data for any other purpose, does not sell it, and does not use it for its own ends.

Table
Type of dataData subjectsPurpose of processing
Contact detailsThe client's employees, customers and suppliersCoordination, communication and task execution
Correspondence and calendarThe client and those corresponding with the clientCarrying out operational tasks and maintaining context
Operational and accounting documentsThe client, its suppliers and its customersIssuing, collecting and tracking
Payment and billing detailsThe client's suppliersMaking payments under authorization
Recordings and transcriptsParticipants in the callDocumentation, continuity of context and quality
Sensitive data, only where provided for a taskAs defined in the instructionThat task alone
03

3. Scope of access and systems

The client specifies in writing the systems to which access is granted, the scope of that access, and the actions Ankora may perform in each system: view only, update, or create new records.

Access is granted to identified individuals only. Each member of the Ankora team works under a personal, identified user in Ankora's systems, in a way that allows the activity to be monitored and controlled.

Every material action is recorded in an audit log with the actor, the time, the entity and the state before and after.

Ankora does not access data that the task does not require, even where it is technically accessible. The list of people holding permissions is available to the client on request.

04

4. Confidentiality

Every person acting on Ankora's behalf who is granted access has signed a personal undertaking of confidentiality and of use of the data for the purpose of the task alone. The undertaking survives the end of their work at Ankora.

When a person's work at Ankora ends, their permissions in Ankora's systems are revoked, and Ankora notifies the authorized contact at the client so that the client can revoke the permissions granted in its own systems.

05

5. Information security

Encryption in transit and at rest, permissions on a need basis, structural separation between clients in the portal, an audit log, rate limiting, and documented periodic security reviews. The full and current detail is in the security and trust page, Document 4.

06

6. Sub-processors

The client approves the use of the sub-processors listed in the privacy policy, section 7.

Ankora's engagement with each sub-processor includes information security and confidentiality undertakings no weaker than those in this addendum. Ankora is responsible for the acts of its sub-processors as for its own.

Ankora will give the client thirty days notice before adding a sub-processor that will have access to the client's data. A client that objects on reasonable security or privacy grounds will say so within fourteen days, and the parties will work in good faith to find an alternative. If none is found, the client may terminate the engagement at the end of the following month, and this will not be treated as a breach on the client's part.

07

7. AI and model training

Ankora integrates AI systems into the operational layer, as described in the privacy policy, section 6.

Ankora does not train models on the client's data. Neither its own models nor those of others. Ankora's engagement with its AI providers prohibits the provider from training models on data that passes through it.

A decision made towards the client or towards a third party is always made by a person. The data passed to the AI systems is limited to what the task requires.

08

8. Recording and documentation

Calls and meetings with the Ankora team are recorded and transcribed, and the record serves operational continuity, quality, and input to the AI systems.

The client is responsible for informing its employees and anyone acting on its behalf who takes part in calls with Ankora, and for obtaining any consent required under the law that applies to the client. A client that asks that its calls, or those of its employees, not be recorded will say so, and Ankora will honor the request.

09

9. Data subject rights

A data subject request that reaches Ankora and concerns the client's data will be passed to the client within three business days and will not be answered by Ankora.

Ankora will assist the client in locating, correcting, exporting or deleting data, to a reasonable extent and at no additional charge, so that the client can meet the response deadline set by the law that applies to it.

10

10. Security incident

Ankora will notify the client of a serious security incident affecting the client's data within twenty four hours of becoming aware of it, including before a full investigation. The notice will include what is known at that point: what happened, which data is involved, what has been done and what is required of the client.

Reporting to the Israeli Privacy Protection Authority and to data subjects is the client's responsibility as owner of the database, and Ankora will assist with the information in its possession.

11

11. Reporting and oversight

Once a year Ankora will report to the client on its compliance with the undertakings in this addendum, and will complete a control questionnaire provided by the client.

The client may conduct an audit, itself or through an auditor on its behalf who is not a competitor of Ankora, once a year, on seven days notice, during service hours, and without prejudicing the confidentiality of other clients. A further audit in the same year, other than one following a security incident, will be at the client's expense.

12

12. Location of the data

The data is stored on the servers of the sub-processors in the United States, as detailed in the privacy policy. The client approves the transfer.

13

13. Term, return and deletion

This addendum is in force for as long as the engagement is active and for as long as Ankora holds the client's data.

On termination Ankora revokes the permissions under its control within three business days, and makes a full export of the data available to the client for up to thirty days.

Ankora will delete the data in its possession within sixty days of termination, other than data the law requires it to retain and backups that are erased in the ordinary backup cycle. On completion of the deletion Ankora will give the client a closing report setting out what was deleted, when, and what was retained and why.

14

14. Liability

Ankora's liability under this addendum is subject to the liability cap in the Service Terms, section 13, except in matters that the law does not permit to be limited.

15

15. Relationship to the other documents

This addendum applies to the processing of personal data only. Every other matter is governed by the Service Terms and the proposal.

In the event of a conflict on a matter of privacy or information security, this addendum prevails over the Service Terms. On every other matter, the Service Terms prevail.

16

Annex A: GDPR supplement

Applies only to a client to whom the GDPR applies. The client is the controller and Ankora is the processor within the meaning of Article 28.

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are as set out in sections 2 and 13 above.

Ankora will assist the client in meeting its obligations under Articles 32 to 36, including security of processing, breach notification and data protection impact assessment, to a reasonable extent and taking account of the information available to it.

Transfers of personal data from the European Union to Israel rely on the European Commission's adequacy decision for Israel, reaffirmed in January 2024 and subject to periodic review. Onward transfer to the sub-processors in the United States relies on those providers' own transfer mechanisms, including standard contractual clauses or certification under the EU and US Data Privacy Framework.

Data transferred to Israel from the European Economic Area is also subject to the Israeli Privacy Protection Regulations on data transferred to Israel from the EEA, and Ankora acts in accordance with them.