BeeMatch.AI返回登录 / Back to sign in
法律文件 · LEGAL

Terms of Service

北京动动脑文化有限公司 · BeeMatch Influencer Marketing Platform

北京动动脑文化有限公司 (the "Company", "we", "us", or "our") operates the BeeMatch influencer‑marketing platform (the "Platform" or "BeeMatch"). BeeMatch is the product and brand name; the legal contracting entity is 北京动动脑文化有限公司. These Terms of Service ("Terms") govern your access to and use of: (i) the BeeMatch website (https://aigrowflow.com/) (the "Website"), (ii) the online Platform, and (iii) all other services and content provided by 北京动动脑文化有限公司 as described on the Website (collectively, the "Services").

By accessing, creating an account, browsing, or otherwise using the Services, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you do not agree, you may not use the Services.

Modifications and Superseding Terms

These Agreements supersede previous online versions, except for separately signed written agreements addressing the same subject matter. Updates will be posted on the Website and take effect upon publication, unless a later effective date is stated.

Eligibility

You represent and warrant that: (i) you have reached the age of majority in your jurisdiction; (ii) if you use the Platform on behalf of an entity, you have authority to bind that entity; (iii) you will comply with these Terms and applicable law; and (iv) the information you provide is true, accurate, current, and complete.

Scope of Services (Influencer Marketing Only)

The Services covered by these Terms consist only of the BeeMatch influencer marketing platform, which helps brand and advertiser users ("Advertisers") discover, evaluate, contact, contract with, and manage suitable social-media creators ("Influencers") for campaigns ("Campaigns"). These Terms apply to both Advertiser and Influencer users unless a provision states otherwise. Campaign-specific requirements, deliverables, usage rights, payment, review, and publication terms displayed in the Platform form part of the agreement for that Campaign. Prior standalone tools or legacy modules not made available through BeeMatch are not offered under these Terms.

Advertiser Terms

Campaign. A Campaign refers to activities related to Influencer content creation and publication sourced via the Platform based on Advertiser requirements. The specific scope, deliverables, timing, and budget are as shown in the Campaign Information you accept on the Platform.

Advertiser Content. Advertiser shall provide accurate and complete promotional materials (logos, brand assets, product information, claims, samples, etc.). You grant 北京动动脑文化有限公司 and assigned Influencers a global, non‑exclusive, royalty‑free license to use such materials solely to perform the Campaign across applicable channels and services. You represent and warrant you have full rights to authorize such use and that all materials and claims are lawful and compliant.

Promotion Services. You may initiate and manage Campaigns via the Platform. Each Campaign’s pricing, rules, and billing model are displayed on the Platform interface and incorporated by reference. By initiating a Campaign, you agree to any Campaign‑specific terms referenced in the interface and to the Promotion Service Framework Agreement in the appendix (if applicable).

Payment of Fees. BeeMatch currently uses a CNY-denominated prepaid wallet for Advertiser payments. Advertisers may recharge the wallet through the payment service provider shown in the Platform (currently Alipay). Amounts may be frozen, debited, released, refunded, or settled according to the applicable Campaign status and Campaign-specific terms. You authorize BeeMatch and its payment service provider to process related transactions. Fees, taxes, refunds, and withdrawal availability are governed by information displayed in the Platform and applicable law.

License Grants

To you. Subject to these Terms, 北京动动脑文化有限公司 grants you a personal, revocable, non‑exclusive, non‑transferable license to access and use the Platform and Services.

To us. Subject to these Terms, you grant 北京动动脑文化有限公司 a worldwide, royalty‑free, sublicensable license to access, collect, store, and use the content and data you upload to the Platform ("User Content") solely for: (A) providing the Services (including Campaign operations, analytics, and reporting), (B) complying with law, and (C) 北京动动脑文化有限公司’s reasonable audit and data‑retention policies.

Ownership

All content provided or displayed through the Platform, including designs, infrastructure, graphics, software, artwork, names, logos and marks (collectively, the "Platform Content"), is owned or licensed by 北京动动脑文化有限公司 and protected by intellectual‑property laws. Except for the limited license above, no rights are granted to you.

Registration and Account

To access the Services you must register an account ("Account"). You agree to: (a) provide accurate, current and complete Account information; (b) maintain the security of your credentials; and (c) promptly notify reply@aigrowflow.com of any suspected breach. 北京动动脑文化有限公司 may disable or suspend your Account at its discretion for risk or violations.

Term and Termination

北京动动脑文化有限公司 may terminate your Account or access to the Services at any time for violations of these Terms, unlawful activity, or risk to the Platform. Termination does not affect accrued rights or obligations. If termination is due to your violation, you may forfeit funds or credits in your account as permitted by law and the applicable Platform rules.

Privacy Policy

Please refer to our Privacy Policy (BeeMatch) for how 北京动动脑文化有限公司 collects, uses, and discloses personal information.

Prohibited Use

You shall not use the Platform to: (a) circumvent access controls or security; (b) overload or interfere with operations; (c) infringe IP or legal rights; (d) submit fraudulent, harmful, or misleading content; (e) scrape or harvest data without permission; or (f) violate applicable social‑network rules when performing Campaigns. 北京动动脑文化有限公司 may suspend access and pursue remedies for prohibited activity.

Third‑Party Websites and Services

The Platform may contain links or integrations to third‑party sites or tools. 北京动动脑文化有限公司 is not responsible for the availability, content, or practices of such third‑party resources.

No Confidentiality of Communications

While 北京动动脑文化有限公司 endeavors to protect information, it cannot guarantee the confidentiality of communications submitted through the Platform. Please do not submit information you consider highly sensitive except where expressly requested and protected.

Disclaimer of Warranties

THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” 北京动动脑文化有限公司 DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON‑INFRINGEMENT. WE DO NOT GUARANTEE ERROR‑FREE SERVICE, UNINTERRUPTED ACCESS, OR SPECIFIC CAMPAIGN PERFORMANCE.

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, 北京动动脑文化有限公司 SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF OR IN CONNECTION WITH THE SERVICES. IN ANY EVENT, 北京动动脑文化有限公司’S TOTAL LIABILITY SHALL NOT EXCEED THE AMOUNTS YOU PAID TO 北京动动脑文化有限公司 FOR THE SERVICES IN THE THREE (3) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY.

Indemnification

You agree to defend, indemnify, and hold harmless 北京动动脑文化有限公司 and its employees, agents, and affiliates from any claims, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from your use of the Services, your violation of these Terms, or your infringement of third‑party rights.

Governing Law and Jurisdiction

These Terms are governed by the laws of the People’s Republic of China. Any dispute shall be submitted to a people’s court with jurisdiction at the domicile of 北京动动脑文化有限公司, unless otherwise required by applicable law.

Entire Agreement and Severability

These Terms constitute the entire agreement between you and 北京动动脑文化有限公司 regarding the Services. If any provision is found unenforceable, the remaining provisions remain in full force and effect.

Appendix (Reference): Promotion Service Framework Agreement

If referenced on the Platform or attached by link, the Promotion Service Framework Agreement supplements Campaign‑specific commercial terms (e.g., milestone billing, taxes, refunds, credits). In case of conflict for a given Campaign, the Campaign Information you accept on the Platform will prevail.

Appendix:Promotion Service Framework Agreement

Last Update: Jul 27, 2026

This Promotion Service Framework Agreement (this “Agreement”) is entered into electronically by and between the service recipient (“Party A”) and 北京动动脑文化有限公司 (“Party B”) (each, a “Party,” and together, the “Parties”). This Agreement sets forth the terms and conditions governing the Parties’ rights and obligations in connection with promotional services delivered via Party B’s designated website(s) and mobile application(s) (the “Platform”).

This Agreement becomes effective immediately when Party A releases a Campaign on the Platform. To the extent the Parties have any prior agreement(s) not fully performed, this Agreement supersedes and replaces such prior agreement(s) as of the Effective Date, and such prior agreement(s) shall be of no further force or effect. Key provisions that materially affect Party A’s rights and obligations are emphasized for convenience.

WHEREAS, Party A intends to expand the reach and recognition of its products, services, or content through lawful, compliant marketing activities;

WHEREAS, Party B is a technology company specializing in marketing and product promotion and, based on Party A’s needs, is able to organize, screen, and manage qualified social-media content creators (each, an “Influencer”) to deliver promotional services;

WHEREAS, the Parties desire to establish a long-term, stable, and compliant cooperation under which Party B or its designated third party promotes Party A’s products, services, or content on owned or authorized media channels to increase exposure;

NOW, THEREFORE, in consideration of the mutual covenants herein, the Parties agree as follows:

Article 1 — Definitions

Unless the context otherwise requires, the following terms have the meanings set forth below:

Party A’s Products: Products, services, or content in which Party A lawfully holds full and valid rights (including, without limitation, ownership and related intellectual property rights) or for which Party A has lawfully obtained authorization to entrust Party B to promote.

Promotion Platform: Media platforms/channels owned by Party B or operated by third parties in cooperation with Party B, on which Influencers may post or launch Creative Content.

Creative Content: Videos, audio works, text, images, and similar materials created for the promotional purposes contemplated by this Agreement, including, without limitation, scripts, drafts, work-in-progress files, final deliverables, project files, assets, subtitles, thumbnails, and related materials.

Campaign Report: A report generated by Party B for specific Campaigns (as defined below) that comprises (a) predicted data derived from the Campaign Information and (b) actual performance data generated by Influencers’ execution; the scope and cadence of reporting shall follow Platform mechanisms.

Publication: An Influencer’s publication of Creative Content on the designated Promotion Platform through the Influencer’s own SNS Account.

SNS Account: A social network service account, including but not limited to Facebook, TikTok, Instagram, Twitter (X), YouTube, and LinkedIn.

Promotion Materials: Materials and information that Party A provides to Party B for the creation of Creative Content, including brand names, logos, trademarks, product samples, images/likenesses, technology, software, product descriptions, and other relevant content.

Campaign / Campaign Information: A specific activity issued by Party B based on Party A’s needs concerning the creation and Publication of Creative Content, together with its parameters, rules, and timeline.

Party A’s Account: The dedicated account opened by Party A on the Platform or on a third-party payment platform designated by Party B, through which Party A can view top-ups, budgets, and balances.

Payment Service Provider: the third-party payment service shown in the Platform interface (currently Alipay). It processes wallet recharge transactions under its own terms and privacy rules.

Platform: Party B’s official website(s) and/or mobile application(s) used by Party A to initiate, manage, and settle Campaigns.

Recommended Influencer: A social-media content creator identified and recommended by Party B to Party A via Platform algorithms and management processes, and who actually undertakes promotional delivery. A Recommended Influencer is an independent third party and does not have an employment relationship with either Party.

Credits: means promotional, non-cash value units that may be granted by Party B or the Platform under publicly posted rules (the “Credit Rules”); Credits are not legal consideration, bear no interest, are non-redeemable for cash, non-transferable, and may only be applied to eligible fees as permitted by the Platform from time to time.

Article 2 — Scope of Cooperation

The Parties may conduct multiple cooperations under this Agreement. The specific content, channels, budget, and schedule for each cooperation shall be governed by the Campaign Information released by Party B on the Platform and confirmed by Party A. Matters not covered by the Campaign Information are governed by this Agreement.

Article 3 — Term

This Agreement is long-term and remains in effect from the Effective Date. The start and end dates of each Campaign are as stated in the corresponding Campaign Information.

Article 4 — Cooperation Requirements

During performance, the Parties may communicate and negotiate via email or other written means regarding product highlights, promotional windows, strategies, and content specifications; the final Campaign Information displayed on the Platform shall prevail.

Party A shall confirm the Campaign Information on the Platform, and Party B shall organize and implement the promotion accordingly. Any items not addressed in the Campaign Information are supplemented by this Agreement.

Campaign Information displayed on the Platform forms an integral part of this Agreement and has the same legal effect as this Agreement.

Article 5 — Payment

Party A shall pay Influencer Price, Transaction Fee, Platform Fee, and/or other applicable charges as set forth herein. Party A may select promotional parameters (e.g., platform, creator language, territory) on the Platform, and Party B will generate a Campaign plan based on Party A’s budget and preferences.

Payment Method. Party A funds its CNY-denominated Platform wallet through the payment service provider shown in the Platform (currently Alipay). After a successful recharge is confirmed, the wallet balance is updated. Amounts for an accepted Campaign may be frozen or debited from the wallet and later released, refunded, or settled according to the Campaign status and confirmed Campaign Information. Any invoice or receipt is provided only where offered in the Platform or required by applicable law.

After service commencement, Party B will track performance periodically and provide Campaign Reports in accordance with Section 1.4.

All amounts under this Agreement are exclusive of taxes(including, without limitation, VAT, GST, sales tax, and similar taxes). Each Party is responsible for its own taxes in accordance with applicable law. Unless expressly agreed otherwise in writing, Party A shall not withhold or deduct any taxes from amounts payable to Party B.

In the event of a failed or unconfirmed recharge or insufficient wallet balance, Party B may decline to start, pause, or terminate the affected Campaign until sufficient funds are available.

Refunds or withdrawals are available only where expressly shown in the Platform or required by applicable law, and may be subject to verification, settlement status, and third-party processing rules.

If Party B offers promotional credits, their validity, permitted use, and expiry are governed by rules displayed when issued. Promotional credits are non-cash, non-transferable, and not withdrawable unless applicable law requires otherwise.

Article 6 — Rights and Obligations of Party A

Party A may initiate Campaign orders on the Platform for products it owns or is duly authorized to promote. If Party A initiates orders for products that it does not own or is not duly authorized to promote (including agency rights), resulting in invalidity or infringement, Party A shall bear all responsibility and loss; Party B reserves all rights and remedies.

Party A shall bear the fees in accordance with Article 5; allocation of transaction fees follows the rules publicly posted on the Platform.

Party A shall provide Promotion Materials timely and in full, and warrants that they are true, lawful, and compliant, do not infringe any third-party rights (including IP, reputation, portrait, privacy), and meet applicable laws, industry standards, and Promotion Platform review standards.

Party A shall ensure that Promotion Materials do not contain viruses, trojans, malicious code, malicious redirects, hidden charges, or other factors that could cause privacy breaches or property loss. If such issues are discovered by a platform during promotion, Party B may immediately suspend services and notify Party A; if the platform asserts claims against Party B, Party A shall assume all liability and indemnify Party B for losses.

Party B shall ensure that Party A is granted a royalty-free, worldwide, transferable, sublicensable license to use, reproduce, display, distribute, adapt, and create derivative works of such Creative Content for marketing, advertising, and promotional purposes during the Term of this Agreement and for 10 years following termination or expiration. Any modifications or derivative works made by Party A shall be undertaken at Party A’s own risk, and Party B shall not be liable for the legality of such modifications.

If a Recommended Influencer fails to deliver conforming Creative Content as agreed (including, without limitation, failure to publish on time or failure to submit required deliverables), Party A may: (a) reschedule the go-live date or cancel the Campaign and request a refund; and (b) obtain aroyalty-free, worldwide, non-exclusive, transferable, sublicensable license to all Creative Content already produced (including scripts, drafts, work-in-progress, partials, and finals) for marketing, advertising, and promotional purposes during the Term and for 10 years following termination or expiration.

Party B shall facilitate and ensure that the Recommended Influencer grants such license to Party A and shall provide reasonable assistance and documentation (including publication links and advertising authorization codes permissions).

Brand Review Timeline. Party A shall review submitted drafts, revisions, or final deliverables and provide feedback, approval, or revision requests within ten (10) business days after submission by the Recommended Influencer or Party B. If Party A fails to provide any feedback, approval, or revision request within such period, the relevant submission shall be deemed pending due to Party A’s delay and shall not constitute non-performance, delay, or breach by Party B or the Recommended Influencer. Any delays, cancellations, or delivery failures caused by Party A’s failure to review in a timely manner may trigger the compensation mechanism set forth in this Agreement.

Revision Scope and Limits. Unless otherwise specified in the Campaign Information, Party A shall be entitled to no more than three (3) reasonable revision rounds per deliverable. Revision requests must remain substantially consistent with the originally approved Campaign Information and may not materially alter the agreed creative direction, workload, production scope, or campaign requirements. Additional revisions, material changes, or newly introduced requirements may require additional fees, revised timelines, or a new Campaign arrangement. For clarity, the revision limitations set forth above shall not apply where the Recommended Influencer repeatedly fails to follow the approved Campaign Information, ignores reasonable revision instructions, submits substantially identical non-compliant content after revision requests, or otherwise fails to make commercially reasonable efforts to complete the deliverables in accordance with the agreed requirements.

Logistics, Samples, and Shipping Risks. Party A acknowledges that Campaigns involving physical products, samples, gifting, or cross-border shipping may be subject to shipping delays, customs clearance issues, import duties, damage in transit, failed delivery attempts, lost packages, or other logistics-related risks arising from third-party carriers, customs authorities, or international transportation processes. Party B acts solely as a coordination platform and shall not be liable for any delays, losses, damages, customs issues, failed deliveries, or additional costs arising from: (a) third-party logistics providers or shipping carriers; (b) customs inspections, duties, seizures, or clearance delays; (c) inaccurate, incomplete, or outdated shipping information; (d) local delivery failures; or (e) other events beyond Party B’s reasonable control. Unless caused by Party B’s gross negligence or willful misconduct, Party A shall bear all costs and risks relating to replacement products, reshipping, customs duties, taxes, handling fees, or additional logistics expenses arising from damaged, delayed, lost, returned, or undelivered samples or products.

Compensation Where Party A Causes Non-Delivery .To preserve Platform order and transactional fairness, Party A agrees that the Platform may automatically settle the following compensation to the Recommended Influencer:(a) If the script or draft has been uploaded but final delivery becomes impossible due to Party A’s failure to review on time or Party A’s cancellation, the Recommended Influencer is entitled to 30% of the order amount;(b) If the final deliverable has been uploaded and Party A fails to grant final approval without a reasonable stated basis, the Recommended Influencer is entitled to 50% of the order amount.Such compensation shall be borne by Party A. After deducting the compensation, any remaining amount will be automatically returned to Party A via the original payment channel.

Logistics and Sampling.(a) Where samples are involved, Party A shall provide accurate and valid tracking numbers on the Platform for logistics tracking.(b) If a sample is lost due to Party A’s fault, neither Party B nor the Recommended Influencer shall be liable. If the tracking record shows delivered but the Recommended Influencer claims non-receipt, the Influencer shall cooperate in providing evidence to determine responsibility.(c) If the Recommended Influencer has received the sample but refuses to deliver, delivers late, or cannot deliver conforming content, the Influencer shall return the sample to Party A and bear related costs, including sample loss, shipping, and handling fees. Party B shall coordinate and supervise the process.

Article 7 — Rights and Obligations of Party B

Party B shall organize and implement promotion in accordance with Campaign Information confirmed by Party A and retains overarching management and final discretion over the promotional process and Platform mechanisms.

Party B shall ensure that the promotion it organizes is lawful and compliant. If, due to Party B’s willful misconduct or gross negligence, the Creative Content is unlawful or infringing(including infringement of IP, personality, or property rights), Party B shall bear corresponding legal liability and compensate Party A for losses, and Party A may terminate this Agreement.

Unless otherwise agreed, Creative Content published by a Recommended Influencer for Party A shall remain available for the retention period specified in the applicable Campaign Information, and may not be deleted or altered except for force majeure or reasons attributable to Party A; in case of breach, Party A may require re-posting.

If service is interrupted due to scheduled/unscheduled maintenance or page adjustments by a Promotion Platform, Party B shall promptly notifyParty A in writing and minimize adverse impact; where alternatives exist, Party B shall actively communicate and assist with adjustments. Upon completion of maintenance/adjustment, Party B shall immediately resume

During the Term and solely to perform this Agreement, Party B may use the Promotion Materials provided by Party A and may sublicense such use to Recommended Influencers or Promotion Platforms as necessary. Except as foregoing, Party B shall not sublicense such materials to third parties.

Party B will select and match creators using its algorithms and management processes within parameters set by Party A; Party A may set blacklists. Platform mechanisms are within Party B’s business discretion, and Party A has no right to require changes.

Party B may display Party A’s name and logo on Party B’s official website, client lists, and marketing materials, and may produce case studies highlighting cooperation under this Agreement, provided that any use of Creative Content itself shall be subject to the scope of licenses granted by the Influencer and applicable law.

Due to the nature of influencer marketing, which involves third-party creators and external platforms, certain uncertainties may affect campaign execution, including delays or non-performance by Influencers. Party B will use commercially reasonable efforts to manage and optimize performance, but does not guarantee that all deliverables will be completed as originally planned.

Article 8 — Confidentiality

“Confidential Information” means all non-public information disclosed by one Party (“Disclosing Party”) to the other (“Receiving Party”) or otherwise obtained by the Receiving Party in connection with this Agreement, including without limitation: business plans, marketing strategies, pricing and settlement terms, unreleased products/features, customer/user/vendor information, organizational and personnel data, financial data, technical materials, source files and project files, workflows and datasets, ad accounts and assets, ad authorization codes/whitelisting permissions/account access, statistics and logs, contracts and legal documents, and all notes, summaries, copies, extracts, and derivatives thereof, whether or not marked “confidential.”

Confidential Information does not include information that: (a) was lawfully in the Receiving Party’s possession prior to disclosure; (b) becomes publicly known through no breach by the Receiving Party; (c) is lawfully received from a third party not under a duty of confidentiality; or (d) is disclosed with the Disclosing Party’s prior written consent.

Use and Need-to-Know.The Receiving Party shall use Confidential Information solely to perform this Agreement and may disclose it only to employees, advisors, and affiliates who need to know the information for such purpose and who are bound by written confidentiality obligations no less protective than those herein. The Receiving Party shall not use Confidential Information for competitive or other improper purposes and shall not reverse engineer, decompile, or make unauthorized copies or adaptations.

The Receiving Party shall protect Confidential Information with safeguards no less stringent than those used to protect its own similar information, including access controls, permission tiering, encryption, logging and backup, data minimization, and appropriate physical and network security. Where personal data or regulated data are involved, the Receiving Party shall comply with applicable data-protection laws and platform rules and execute data-processing terms if required.

Compelled Disclosure.If legally compelled (by law, court, or regulator) to disclose, the Receiving Party shall, to the extent permitted by law, promptly notify the Disclosing Party and disclose only what is legally necessary, using reasonable efforts to seek confidential treatment or protective orders.

Return/Destruction.Upon the Disclosing Party’s written request, completion of cooperation, or termination of this Agreement (whichever occurs first), the Receiving Party shall cease use and return or destroy all Confidential Information (including backups, extracts, and derivatives) and provide written certification within a reasonable time. Where retention is legally required, the Receiving Party shall continue to honor confidentiality during the retention period.

Breach; Remedies.Any breach of this Article constitutes a material breach. In addition to damages (including reasonable attorneys’ fees and costs), the Disclosing Party is entitled to injunctive and equitable relief without the need to prove the inadequacy of monetary damages.

Confidentiality obligations take effect upon first disclosure and continue until the information lawfully becomes public. If public timing is uncertain, confidentiality shall survive for not less than five (5) years from termination of this Agreement. Obligations concerning trade secrets, personal data, ad accounts, and authorization codes shall survive as long as permitted by law.

Protective Disclosure for Rights Enforcement.If Party A initiates orders for products not owned or duly authorized and thereby infringes a legitimate brand owner, Party B may, to the minimum extent necessary for rights-enforcement or compliance, disclose relevant information about Party A to such brand owner and competent authorities and pursue damages.

Article 9 — Liability for Breach

A Party that breaches this Agreement shall, without prejudice to the other Party’s rights and remedies at law or in equity, be liable to indemnify and hold the other Party harmless from and against all losses, damages, costs, and expenses (including reasonable attorneys’ fees, investigation costs, notarization, litigation/arbitration fees, and travel expenses) arising from such breach.

Special Provision (Non-Compliant Materials by Party A).If Party A’s Promotion Materials are unlawful, contrary to public order and morality, infringe third-party rights, or contain false content:(a) Party B may instruct Recommended Influencers to modify, remove, or cease publishing related Creative Content and may report to the Promotion Platform and regulators and take reasonable measures to mitigate adverse effects;(b) Party B may terminate cooperation with Party A, and fees already paid will not be refunded; and(c) Party A shall be liable for all losses incurred by Party B, including any and all liabilities asserted by third parties (including Recommended Influencers), such as direct, indirect, incidental, consequential, special, exemplary, or punitive damages; loss of profits, use, or data; fines and penalties; and other liabilities.

Article 10 — Termination

This Agreement may be amended or terminated early by mutual written agreement of the Parties.

If performance of all or part of this Agreement becomes impossible due to force majeure or changes in applicable laws or regulatory policies, the Parties may terminate this Agreement upon consultation.

Absent a specific contrary provision, the non-breaching Party may immediately terminate this Agreement if:(a) the breaching Party violates applicable laws or regulations and thereby causes material harm to the non-breaching Party’s lawful rights and interests; or(b) the breaching Party fails to cure within a reasonable period after written notice from the non-breaching Party.

Termination or expiration of this Agreement shall not affect any liability already accrued, including liability for breach, or the settlement of amounts then due and payable.

Article 11 — Governing Law and Dispute Resolution

This Agreement, including its formation, validity, performance, interpretation, and dispute resolution, shall be governed by the laws of the People’s Republic of China, without regard to its conflict-of-law rules.

Any dispute arising out of or relating to this Agreement shall first be resolved through good-faith negotiation. If the dispute cannot be resolved amicably, either Party may submit it to a people’s court with jurisdiction at Party B’s domicile.

Article 12 — Miscellaneous

Any matters not addressed herein may be set out in written addenda executed by the Parties. In the event of a conflict between an addendum and this Agreement, the addendum shall prevail.

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

This Agreement is concluded electronically. By signing in, creating or using an Account, initiating a Campaign, or continuing to access or use the Platform after this Agreement is made available, Party A acknowledges that it has had an opportunity to read it and agrees to be bound.

Party B may update this Agreement for operational or compliance reasons and will notify Party A via Platform notice, in-app message, or email. Updates apply from the stated effective date. If Party A objects, it shall cease use before the effective date and follow Platform procedures to terminate cooperation; continued use after the effective date constitutes acceptance of the update.

Data Processing Agreement

This Data Processing Agreement (the “DPA”) constitutes an integral part of all agreements between Customer (as defined in the Promotion Service Framework Agreement or otherwise identified on the signature block below) and 北京动动脑文化有限公司 (the “Processor” or “BeeMatch”), including the Promotion Service Framework Agreement or under any services agreement or similar agreement (collectively “Agreement”), and reflects the Parties’ agreement with respect to the Processing of Controller Data.

In providing the Services to Customer pursuant to the Agreement, BeeMatch may Process Personal Data on behalf of Customer and the Parties agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith. This DPA supplements the Agreement and in the event of any conflict between the terms of this DPA and the terms of the Agreement, the terms of this DPA prevail with regard to the specific subject matter of this DPA. This DPA is effective on the date that it, or the Agreement that references and incorporates it, has been duly executed by both Parties (“Effective Date”), and amends, supersedes and replaces any prior agreement relating to data processing and/or data protection entered into by the Parties.

DEFINITIONS

Any capitalized terms used but not defined in this DPA has the meaning provided to it in the Agreement,

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. Control, for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

“Applicable Data Protection Law” means (a) all data protection laws and regulations applicable to the European Economic Area and Switzerland, including (i) the General Data Protection Regulation 2016/679 (“GDPR”), and EU Member State laws supplementing the GDPR; (b) the UK Data Protection Act of 2018, and the UK GDPR (collectively “UK Data Protection Laws”); and (c) any other laws and regulations applicable to Processor’s Processing of Controller Data under the Agreement.

“Authorized Affiliate” means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Customer, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.

“California Privacy Law” means the California Consumer Privacy Act until January 1, 2023, and thereafter will refer to the California Privacy Rights Act.

“Controller” as used in this DPA, means Customer.

“Controller Data” means any Personal Data Processed by Processor on behalf of Customer pursuant to or in connection with the Agreement.

“Customer” means the entity which determines the purposes and means of the Processing of Personal Data and includes any Authorized Affiliates of the Customer, and to the extent applicable includes a “Business” as defined under California Privacy Law.

“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller Data transmitted, stored or otherwise processed by Processor.

“Permitted Purpose” means the use of the Controller Data to the extent necessary for provision of the Services by Processor to the Controller, including but not limited to personalized content generation, automated marketing communications, integration with Third Party Products (as defined in the underlying Agreement) and/or Controller’s third-party systems and platforms, and other features and functionalities provided as part of the Services.

“Personal Data” means any information relating to an identified or identifiable natural person that relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person.

“Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, sharing, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Processor” means 北京动动脑文化有限公司 and its Affiliates, which Process Personal Data on behalf of the Customer, and to the extent applicable, includes a “Service Provider” as defined under the California Privacy Law.

“Regulator” means any supervisory authority with authority under Applicable Data Protection Law over all or any part of the provision or receipt of the Services or the Processing of Personal Data.

“Restricted Transfer” means: (i) where the EU GDPR applies, transferring Personal Data from the EEA to a country outside the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, transferring Personal Data from the United Kingdom to any other country which is not subject based on adequacy regulations under Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss Federal Act on Data Protection of June 19, 1992 (‘Swiss DPA”) applies, transferring Personal Data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.

“Services” means the products and services that are ordered by Controller through a link or via an Order pursuant to the Agreement and made available online by Processor.

Sub-processor” means any third-party data processor engaged by Processor, who receives Personal Data from Processor for processing on behalf of Controller and in accordance with Controller's instructions (as communicated by Processor) and the terms of its written subcontract.

The terms, “Commission”, “Data Subject”, “Member State”, and “Supervisory Authority” shall have the same meaning as in the Applicable Data Protection Laws, and their cognate terms shall be construed accordingly.

PURPOSE

2.1 Controller and Processor have entered into the Agreement pursuant to which Controller is granted a right to access and use the Services. In providing the Services, Processor will engage, on behalf of Controller, in the processing of Personal Data submitted to and stored within the Services by Controller.

2.2 The Parties are entering into this DPA to ensure that the Processing by Processor of Controller Data, within the Services by Controller and/or on its behalf, is done in a manner compliant with Applicable Data Protection Law and its requirements regarding the collection, use and retention of Personal Data of Data Subjects.

AUTHORITY

3.1 Roles of the Parties

To the extent the GDPR or UK Data Protection Laws apply to the Controller Data, the Parties acknowledge and agree that Customer is a Controller and BeeMatch is a Processor acting on behalf of Customer. When Customer is acting as a Processor of Controller Data, BeeMatch is a sub-processor of the Customer.

For purposes of California Privacy Law, BeeMatch will act as a Service Provider in its performance of its obligations under the Agreement. BeeMatch (i) will only use Controller Data to provide the Services under the Agreement; (ii) will not collect, retain, use, sell, disclose or otherwise process any Controller Data, for any purpose other than providing the Services under the Agreement, or as otherwise permitted. Notwithstanding anything to the contrary in the Agreement (including this DPA), Controller acknowledges that Processor shall have a right to Process Personal Data in relation to the support and/or use of the Services for its legitimate business purposes, such as billing, account management, technical support, product development, sales and marketing, personalization features, content generation, third-party system integrations, and processing business contact information to provide personalized services. BeeMatch understands the restrictions in this Section 3.1(b) and certifies that it understands its obligations under the California Privacy Law and will comply with them.

3.2 Controller’s Instructions.Customer represents and warrants that (i) it has complied, and will continue to comply, with all applicable laws, including Applicable Data Protection Law, in respect of its Processing of Controller Data and any Processing instructions it issues to Processor; (ii) it has provided, and will continue to provide, all notice and has obtained, and will continue to obtain, all consents and rights necessary under Applicable Data Protection Law for Processor to process Controller Data for the purposes described in the Agreement; and (iii) it has the appropriate legal basis under Applicable Data Protection Law to share business contact information and other Personal Data with Processor, including any Personal Data obtained from any Third Party Products and/or third-party systems, integrations, or databases, and that such sharing complies with all applicable privacy laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Controller Data and the means by which Customer acquired the Controller Data. Controller specifically acknowledges that its use of the Services will not violate the rights of any Data Subject that has opted-out from sales or other disclosures of Personal Data, to the extent applicable under the California Privacy Law.

3.3 Purpose Limitation. Processor shall process Controller Data only in accordance with Customer’s documented lawful instructions as set forth in this DPA, for Permitted Purposes, as necessary to comply with applicable law, or as otherwise agreed to in writing. The Parties agree that the Agreement and this DPA set out Customer’s complete and final instructions to Processor in relation to the processing of Controller Data, and processing outside the scope of these instructions (if any) shall require prior written agreement between the Parties.

3.4 Data Subject and Regulator Requests.Customer shall be responsible for communications and leading any efforts to comply with all requests made by Data Subjects under the Applicable Data Protection Law, and all communications from Regulators that relate to the Controller Data.

OBLIGATIONS OF PROCESSOR

4.1 Confidentiality. Processor will restrict access to the Controller Data to its personnel who need access to meet Processor’s obligations under the Agreement. Processor shall take commercially reasonable steps to ensure the reliability of any Processor personnel engaged in the Processing of Controller Data.

4.2 Disclosure to Third Parties. Processor will not disclose Controller Data to third parties except as permitted by this DPA or the Agreement. If requested or required by a competent governmental authority to disclose Controller Data, to the extent legally permissible and practicable, Processor will provide Customer with sufficient prior written notice in order to permit Customer the opportunity to oppose any such disclosure.

4.3 Retention. Processor will retain Controller Data only for as long as the Customer deems it necessary for the Permitted Purpose, or as required by Applicable Data Protection Law. At the termination of this DPA, or upon Customer’s written request, Processor will either destroy or return the Controller Data to Customer, unless legal obligations require storage of the Controller Data.

4.4 Data Subject and Regulator Requests. Processor shall, to the extent legally permitted, promptly notify Controller in writing of any complaints, questions or requests received from Data Subjects or Regulators regarding the Controller Data. In taking into account the nature of the Processing and to the extent reasonably possible, Processor will provide Controller with commercially reasonable assistance in relation to the handling of a Data Subject’s request. To the extent Controller, in its use of the Services, does not have the ability to correct, block or delete Controller Data, Processor shall comply with any commercially reasonable request by Controller to facilitate such actions to the extent Processor is legally permitted to do so.

4.5 Data Protection Impact Assessment. To the extent required under the Applicable Data Protection Law, upon Customer’s request, Processor will provide reasonable assistance to Customer necessary for Customer to fulfill its obligation under the Applicable Data Protection Law to carry out a data protection impact assessment related to Customer’s use of the Services, to the extent Customer does not otherwise have access to the relevant information, and to the extent such information is available to Processor.

4.6 Security. Processor will implement and maintain appropriate technical, physical and administrative measures to protect Controller Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access (a "Data Security Breach"), provided that such measures shall take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, so as to ensure a level of security appropriate to the risks represented by the processing and the nature of the Controller Data to be protected.

Customer acknowledges that the security measures are subject to technical progress and development and that Processor may update or modify the security measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by Customer. Customer is responsible for reviewing the information made available by Processor relating to data security and making an independent determination as to whether the Services meet Controller’s requirements and legal obligations under Applicable Data Protection Law.

Notwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Services, including securing its account authentication credentials, protecting the security of Controller Data when in transit to and from the Services and taking any appropriate steps to securely encrypt or backup any Controller Data uploaded to the Services.

DATA BREACH

5.1 Data Breach. If Processor becomes aware of any Data Breach, Processor will promptly: notify Customer of the Data Breach, but in no event later than seventy-two (72) hours after Processor has confirmed a Data Breach impacting Controller Data; investigate the Data Breach and provide Customer with information about the Data Breach; and take reasonable steps to mitigate the effects and to minimize any damage resulting from the Data Breach. Processor’s obligation to report or respond to a Data Breach under this Section is not and will not be construed as an acknowledgement by Processor of any fault or liability with respect to the Data Breach.

5.2 Coordination. Processor will provide reasonable assistance to Customer in fulfilling its obligations to notify Data Subjects and the relevant authorities in relation to a Data Breach, provided that nothing in this section shall prevent either party from complying with its obligations under the Applicable Data Protection Laws. The Parties agree to coordinate in good faith on developing the content of any related public statements.

5.3 Caused by Controller.The obligations in this section shall not apply to a Data Breach that is caused by Customer.

AUDITS

Customer may audit Processor’s compliance with this DPA up to once per year, unless requested by a Supervisory Authority. Such an audit will be conducted by an independent third party ("Auditor") reasonably acceptable to Processor. Before the commencement of any such on-site audit, Customer must submit in writing a detailed proposed audit plan to Processor at least 30 business days in advance of the proposed audit date. The proposed audit plan must describe the proposed scope, duration and date of the audit, as well as the proposed Auditor. Processor will review the proposed audit plan and provide Customer with any concerns or questions and will work cooperatively with Customer to agree on a final audit plan. Prior to the start of an audit, the Parties will agree to reasonable time, duration, place and manner conditions for the audit, and a reasonable reimbursement rate payable by Customer to Processor for Processor’s audit expenses. The results of the audit and all information reviewed during such inspection will be deemed Processor’s confidential information, and subject to the Confidentiality provisions in the Agreement. Notwithstanding any other terms, the Auditor may only disclose to the Customer any specific violations of the DPA, if any, and the basis for such findings, and shall not disclose to the Customer any of the records or information reviewed during the inspection.

USE OF SUB-PROCESSORS

7.1 General Consent.Customer acknowledges and agrees that Processor may appoint Sub-processors to assist it in providing the Service and Processing Controller Data provided that such Sub-processors agree to (a) act only on Processor’s instructions when Processing the Controller Data (which instructions shall be consistent with Controller's processing instructions to Processor); and (b) protect the Controller Data to a standard consistent with the requirements of this DPA.

7.2 Sub-processor Information. Processor will make information about material Sub-processors available on request where required by applicable law or written contract.

7.3 Changes. Where required by applicable law or written contract, Processor will provide notice of material Sub-processor changes and a reasonable opportunity for Customer to raise data-protection objections.

7.4 Liability. Processor shall be liable for the acts and omissions of its Sub-processors use to provide the Services to the same extent Processor would be liable if performing the services of each sub-processor directly under the terms of this DPA, except as otherwise set forth in the Agreement.

INTERNATIONAL PROVISIONS

8.1 Jurisdiction Specific Terms.To the extent Processor Processes Controller Data originating from and protected by Applicable Data Protection Law in one of the jurisdictions listed in Schedule 4 (Jurisdiction Specific Terms) of this DPA, the terms specified in Schedule 5 with respect to the applicable jurisdiction(s) apply in addition to the terms of this DPA.

8.2 Restricted Transfers. To the extent Customer’s use of the Services involves a Restricted Transfer of Controller Data, the terms set forth in Schedule 4 (Cross Border Transfer Mechanisms) will apply. In the event of any conflict or inconsistency between this DPA and the terms set forth in Schedule 4, the terms in Schedule 4 shall apply.

LIMITATION ON LIABILITY

9.1 In no event will either Party or their respective directors, officers, agents, or employees be liable to the other party for any reason, whether in contract or in tort for any claims or liability arising out of or based upon this DPA, excess of the amount actually paid by the Customer to Processor in the twelve months preceding the first incident out of which the liability arose, regardless of the form in which any legal or equitable action may be brought.

9.2 For the avoidance of doubt, Processor’s and its Affiliates’ total liability for all claims from the Customer and all of its Authorized Affiliates arising out of or related to the Agreement and each DPA shall apply in the aggregate for all claims under both the Agreement and all DPAs established under this Agreement, including by Customer and all Authorized Affiliates, and, in particular, shall not be understood to apply individually and severally to Customer and/or to any Authorized Affiliate that is a contractual party to any such DPA.

MISCELLANEOUS

10.1 Any provision of this DPA that is prohibited or unenforceable in any jurisdiction shall, as to that jurisdiction alone, be ineffective to the extent of such prohibition or unenforceability without invalidating the remaining provisions hereof, and any such prohibition or unenforceability in any jurisdiction shall not invalidate or render unenforceable such provision in any other jurisdiction. The parties will attempt in good faith to agree upon a valid and enforceable provision that is a reasonable substitute and shall incorporate such substitute provision into this DPA.

10.2 This DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by Applicable Data Protection Law.

10.3 Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Law, in the name and on behalf of its Authorized Affiliates, if and to the extent BeeMatch processes Personal Data for which such Authorized Affiliates qualify as the Controller.

10.4 This DPA may not be amended or modified except by the mutual agreement of the Parties; provided, however, Customer will be notified thirty (30) days in advance of any amendments or modifications to this DPA, which shall take effect in the next billing cycle, and Customer’s continued use of the Services shall constitute acceptance of such amendments and/or modifications. This DPA may be executed in counterparts. The terms and conditions of this DPA are confidential and each Party agrees and represents, on behalf of itself, its employees and agents to whom it is permitted to disclose such information that it will not disclose such information to any third party; provided, however, that each Party shall have the right to disclose such information to its officers, directors, employees, auditors, attorneys and third party contractors who are under an obligation to maintain the confidentiality thereof and further may disclose such information as necessary to comply with an order or subpoena of any administrative agency or court of competent jurisdiction or as reasonably necessary to comply with any applicable law or regulation. Controller may not, directly or indirectly, by operation of law or otherwise, assign all or any part of its rights under this DPA or delegate performance of its duties under this DPA without Processor's prior consent, which consent will not be unreasonably withheld. Processor may, without Controller's consent, assign this DPA to any affiliate or in connection with any merger or change of control of Processor or the sale of all or substantially all of its assets provided that any such successor agrees to fulfil its obligations pursuant to this DPA. Subject to the foregoing restrictions, this DPA will be fully binding upon, inure to the benefit of and be enforceable by the Parties and their respective successors and assigns.

Unless otherwise incorporated by reference in an Agreement, the Parties' authorized signatories have duly executed this DPA as of the Effective Date:

北京动动脑文化有限公司

Customer

Signature: ______________________________

Customer: ______________________________

Print Name: _____________________________]

Signature: ______________________________

Title: ___________________________________

Print Name: _____________________________]

Title: ___________________________________

Schedule 1 – Details of Processing

Categories of Data Subjects. The personal data transferred concern the following categories of Data Subjects: The categories of data subjects are within the control of the Controller and may include customers, prospects, business contacts, employees, and other individuals about whom data is provided to Processor by or at the direction of the Controller pursuant to the Agreement, including through Third Party Products and/or third-party system integrations, data uploads, or in connection with the Services.

Types of Personal Data Transferred. The personal data transferred concern the following categories of data: the categories of Personal Data are within the control of the Controller and may include contact information (such as names, email addresses, phone numbers), professional details (such as job titles, company affiliations, business roles), business relationship data, communication preferences, and other data relating to individuals to the extent provided to Processor by or at the direction of the Controller pursuant to the Agreement, including through Third Party Products and/or third-party system integrations, data uploads, or in connection with the Services.

Sensitive Data Transferred. The personal data transferred concern the following special categories of data: the categories of Personal Data are within the control of the Controller and may include data relating to individuals to the extent provided to Processor by or at the direction of the Controller pursuant to applicable terms of service between them.

Frequency of the Transfer. Continuous.

Nature of Processing. The Personal Data transferred will be subject to the following basic processing activities: Processor will Process Controller Data as necessary to perform the Services pursuant to the Agreement, and as further instructed by Customer in its use of the Services. The processing operations include personalization services, content generation, analysis and recommendations, integration with Third Party Products and/or third-party systems and platforms, and other Services that are used by the Controller.

Purpose of Processing. The purpose of the Processing of Controller Data by Processor is to provide Customer with the Services under the Agreement, including personalized content creation, business communication enhancement, and other features and functionalities provided as part of the Services.

Duration of the Processing. The Term of the Agreement, plus the period from the expiry of such Term until deletion of all Controller Data by the Processor in accordance with the DPA.

Schedule 2 – Technical and Organizational Security Measures

Access Control

BeeMatch limits access to production systems and customer data through account- and role-based controls. Access is granted only for authorized purposes and should be adjusted or removed when it is no longer required.

Change Management

Application source code is maintained in version control, and production releases are built and deployed through an automated workflow.

Transport and Credential Protection

Public access to the Platform is provided over HTTPS. User passwords are salted and hashed using scrypt; plaintext passwords are not stored.

Monitoring and Incident Handling

Service health checks and application/container logs support operations, troubleshooting, and incident investigation.

Vulnerability Handling

Reported vulnerabilities are assessed and remediated based on severity, risk, and available mitigations.

Schedule 3 – Service Providers and Sub-processors

BeeMatch may use service providers and sub-processors to support hosting, AI-enabled features, communications, social-data integrations, analytics, and payments. Such providers are engaged subject to applicable contractual and data-protection requirements. Additional information will be made available on request where required by applicable law or contract.

Schedule 4 – Cross Border Transfer Mechanisms

Definitions

“EC” means the European Commission.

“EEA” means the European Economic Area.

“EEA Personal Data” is Controller Data collected from data subjects when they are located in the EEA.

“Standard Contractual Clauses” means (i) where the EU GDPR applies, the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for transferring personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and of the Council (“EU SCC”); (ii) where the UK GDPR applies, the International Data Transfer Agreement: Controller to Processor under Section 119A of the Data Protection Act 2018 (“UK SCC”); and (iii) where the Swiss DPA applies, the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner (“Swiss SCC”).

“Swiss Personal Data” means Controller Data collected from data subjects when they are located in Switzerland.

“UK Personal Data” means Controller Data collected from data subjects when they are located in the United Kingdom.

Cross-Border Data Transfer Mechanisms

2.1 EEA Personal Data. The Parties agree that the Standard Contractual Clauses will apply to Controller Data that is transferred via the Services from the EEA or Switzerland, either directly or via onward transfer, to any country or recipient outside the EEA or Switzerland that is: (a) not recognized by the European Commission (or, in the case of transfers from Switzerland, the competent authority for Switzerland) as providing an adequate level of protection for Personal Data. To the extent applicable, the Standard Contractual Clauses will be deemed entered into (and incorporated into this Addendum by this reference) and are deemed executed by each of the Parties acting on their own behalf and on behalf of their Affiliates (where applicable) without the need for any further signature from either party and completed as follows:

Module Two (Controller to Processor) of the Standard Contractual Clauses will apply where Customer is a Controller of Controller Data and BeeMatch is Processing Controller Data.

Module Three (Processor to Processor) of the Standard Contractual Clauses will apply where Customer is a Processor of Controller Data and BeeMatch is Processing Controller Data.

For each Module, where applicable:

in Clause 7 of Standard Contractual Clauses, the optional docking clause will not apply;

the audits described in Clause 8.9(c) and (d) of the SCC shall be carried out in accordance with Section 6 of the DPA;

in Clause 9 of the Standard Contractual Clauses, Option 2 will apply and the time period for prior notice of sub-processor changes will be as set forth in the DPA;

in Clause 11 of the Standard Contractual Clauses, the optional language will not apply;

the liability described in Clause 12 shall in no event exceed the limitations set forth in the DPA, and that under no circumstances and under no legal theory (whether in contract, tort, negligence or otherwise) will either party to this DPA, or their Affiliates, officers, directors, employees, agents, service providers, suppliers, or licensors be liable to the other party or any third party for any lost profits, lost sales of business, lost data (being data lost in the course of transmission via Customer’s systems or over the Internet through no fault of Supplier), business interruption, loss of goodwill, or for any type of indirect, incidental, special, exemplary, consequential or punitive loss or damages, regardless of whether such party has been advised of the possibility of or could have foreseen such damages. For the avoidance of doubt, this section shall not be construed as limiting the liability of either party with respect to claims brought by data subjects;

the certification of deletion of Controller Data that is described in Clause 16(d) of the SCC shall be provided by Processor to Customer only upon Customer’s request;

in Clause 17 (Option 1), the Standard Contractual Clauses will be governed by Irish law;

in Clause 18(b) of the Standard Contractual Clauses, disputes will be resolved before the courts of Ireland;

in Annex I, Part A of the Standard Contractual Clauses:

Data Exporter: Customer.

Contact details: See signature line of DPA.

Data Exporter Role: The Data Exporter’s role is set forth in Section 3 (Relationship of the Parties) of this DPA.

Signature and Date: By entering into the DPA, Data Exporter is deemed to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Agreement.

Data Importer: Processor (BeeMatch)

Contact details: 北京动动脑文化有限公司, reply@aigrowflow.com

Data Importer Role: The Data Importer’s role is set forth in Section 3 (Relationship of the Parties) of this DPA.

Signature and Date: By entering into the DPA, Data Importer is deemed to have signed these Standard Contractual Clauses, incorporated herein, including their Annexes, as of the Effective Date of the DPA.

in Annex I, Part B of the Standard Contractual Clauses:

The categories of data subjects: see Schedule 1 (Details of Processing) of this DPA.

The Sensitive Data transferred: see Schedule 1 (Details of Processing) of this DPA.

The frequency of the transfer is a continuous basis for the duration of the Agreement.

The nature of the processing: see Schedule 1 (Details of Processing) of this DPA.

The purpose of the processing: see Schedule 1 (Details of Processing) of this DPA.

The period for which the Personal Data will be retained: see Schedule 1 (Details of Processing) of this DPA.

in Annex I, Part C of the Standard Contractual Clauses: The Irish Data Protection Commission will be the competent supervisory authority;

Schedule 2 (Technical and Organizational Security Measures) of this Addendum serves as Annex II of the Standard Contractual Clauses; and

in relation to Swiss Personal Data:

For purposes of Annex I.C under Clause 13 of Standard Contractual Clauses insofar as the data transfer is governed by the Switzerland Federal Act on Data Protection of 19 June 1992 (SR 235.1; FADP) or the FADP’s revised 25 September 2020 version, the Supervisory Authority shall be Switzerland’s Federal Data Protection and Information Commissioner (FDPIC);

The term “member state” must not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in Switzerland in accordance with Clause 18(c) of the Standard Contractual Clauses. The Standard Contractual Clauses shall also protect the data of Switzerland legal entities until the entry into force of the 25 September 2020 revised version of the Federal Act on Data Protection (revised FADP). Any references in the Standard Contractual Clauses to “Directive 95/46/EC” or “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss DPA.

2.2 UK Personal Data. The parties agree that the Information Commissioner’s Office’s International Data Transfer Agreement, referred to hereafter as Standard Contractual Clauses, will apply to UK Personal Data that is transferred via the Services from the United Kingdom, either directly or via onward transfer, to any country or recipient outside the United Kingdom that is not recognized by the ICO as providing an adequate level of protection for Personal Data. To the extent applicable, the Standard Contractual Clauses will be deemed entered into (and incorporated into this DPA by this reference) and completed as follows:

PART 1: TABLES

Table 1: Parties

Start Date

See Effective Date of the DPA

The Parties

Data Exporter (Controller)

BeeMatch - Data Importer (Processor)

Parties’ details

See Section 2.1(c)(viii), above.

See Section 2.1(c)(viii), above.

Key Contact

See Section 2.1(c)(viii), above.

See Section 2.1(c)(viii), above.

Table 2: Transfer Details

UK country’s law that governs the IDTA:

☒ England and Wales

☐ Northern Ireland

☐ Scotland

Primary place for legal claims to be made by the Parties

☒ England and Wales

☐ Northern Ireland

☐ Scotland

The status of the Exporter

In relation to the Processing of the Transferred Data:

☒ Exporter is a Controller

☐ Exporter is a Processor or Sub-Processor

The status of the Importer

In relation to the Processing of the Transferred Data:

☐ Importer is a Controller

☒ Importer is the Exporter’s Processor or Sub-Processor

☐ Importer is not the Exporter’s Processor or Sub-Processor (and the Importer has been instructed by a Third Party Controller)

Whether UK GDPR applies to the Importer

☒ UK GDPR applies to the Importer’s Processing of the Transferred Data

☐ UK GDPR does not apply to the Importer’s Processing of the Transferred Data

Linked Agreement

If the Importer is the Exporter’s Processor or Sub-Processor – the agreement(s) between the Parties which sets out the Processor’s or Sub-Processor’s instructions for Processing the Transferred Data:

Name of agreement: DPA to which this Schedule 4 is attached.

Date of agreement: Same as above.

Parties to the agreement: Same as above.

Reference (if any): None.

If the Exporter is a Processor or Sub-Processor – the agreement(s) between the Exporter and the Party(s) which sets out the Exporter’s instructions for Processing the Transferred Data: (complete if applicable otherwise put N/A)

Name of agreement:

Date of agreement:

Parties to the agreement:

Reference (if any):

Term

The Importer may Process the Transferred Data for the following time period:

☒ the period for which the Linked Agreement is in force

☐ time period:

☐ (only if the Importer is a Controller or not the Exporter’s Processor or Sub-Processor) no longer than is necessary for the Purpose.

Ending the IDTA before the end of the Term

See Termination provision in the DPA to which this Schedule 4 is attached.

Ending the IDTA when the Approved IDTA changes

See Termination provision in the DPA to which this Schedule 4 is attached.

Can the Importer make further transfers of the Transferred Data?

☐ The Importer MAY transfer on the Transferred Data to another organisation or person (who is a different legal entity) in accordance with Section 16.1 (Transferring on the Transferred Data).

☒ The Importer MAY NOT transfer on the Transferred Data to another organisation or person (who is a different legal entity) in accordance with Section 16.1 (Transferring on the Transferred Data).

Specific restrictions when the Importer may transfer on the Transferred Data

The Importer MAY ONLY forward the Transferred Data in accordance with Section 16.1:

☒ if the Exporter tells it in writing that it may do so.

☐ to:

☐ to the authorised receivers (or the categories of authorised receivers) set out in:

☐ there are no specific restrictions.

Review Dates

☐ No review is needed as this is a one-off transfer and the Importer does not retain any Transferred Data

First review date:

The Parties must review the Security Requirements at least once:

☐ each month(s)

☐ each quarter

☐ each 6 months

☒ each year

☐ each year(s)

☐ each time there is a change to the Transferred Data, Purposes, Importer Information, TRA or risk assessment

Table 3: Transferred Data

Transferred Data

See Schedule 1 of the DPA to which this Schedule 4 is attached.

Special Categories of Personal Data

See Schedule 1 of the DPA to which this Schedule 4 is attached.

Relevant Data Subjects

See Schedule 1 of the DPA to which this Schedule 4 is attached.

Purpose

See Schedule 1 of the DPA to which this Schedule 4 is attached.

Table 4: Security Requirements

Security of Transmission

See Schedule 2 of the DPA to which this Schedule 4 is attached.

Security of Storage

See Schedule 2 of the DPA to which this Schedule 4 is attached.

Security of Processing

See Schedule 2 of the DPA to which this Schedule 4 is attached.

Organisational security measures

See Schedule 2 of the DPA to which this Schedule 4 is attached.

Technical security minimum requirements

See Schedule 2 of the DPA to which this Schedule 4 is attached.

Updates to the Security Requirements

☒ The Security Requirements will update automatically if the information is updated in the Linked Agreement referred to.

☐The Security Requirements will NOT update automatically if the information is updated in the Linked Agreement referred to. The Parties must agree a change under Section 5.3.

PART 2: EXTRA PROTECTION CLAUSES

Extra Protection Clauses:

(i) Extra technical security protections

N/A

(ii) Extra organisational protections

N/A

(iii) Extra contractual protections

N/A

PART 3: COMMERCIAL CLAUSES

Commercial Clauses

See Agreement to which the DPA is attached.

PART 4: MANDATORY CLAUSES

The template IDTA A1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 5.4. By entering into the DPA, the parties are deemed to have signed the IDTA, incorporated herein by reference, as of the Effective Date of the Agreement.

Schedule 5 – Jurisdiction Specific Terms

Australia

1.1 The definition of “Applicable Data Protection Law” includes the Australian Privacy Principles and the Australian Privacy Act (1988).

1.2 The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.

Brazil

2.1 The definition of “Applicable Data Protection Law” includes the Lei Geral de Proteção de Dados (LGPD).

2.2 The definition of “Data Breach” includes a security incident that may result in any relevant risk or damage to data subjects.

2.3 The definition of “Processor” includes “operator” as defined under Applicable Data Protection Law.

Canada

3.1 The definition of “Applicable Data Protection Law” includes the Federal Personal Information Protection and Electronic Documents Act (PIPEDA).

European Economic Area (EEA)

4.1 The definition of “Applicable Data Protection Law” includes the General Data Protection Regulation (EU 2016/679) (“GDPR”).

4.2 Notwithstanding anything to the contrary in this DPA or in the Agreement (including, without limitation, either party’s indemnification obligations), neither party will be responsible for any GDPR fines issued or levied under Article 83 of the GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the GDPR.

Israel

5.1 The definition of “Applicable Data Protection Law” includes the Protection of Privacy Law (PPL).

5.2 The definition of “controller” includes “Database Owner” as defined under Applicable Data Protection Law.

5.3 The definition of “processor” includes “Holder” as defined under Applicable Data Protection Law.

Japan

6.1 The definition of “Applicable Data Protection Law” includes the Act on the Protection of Personal Information (APPI).

6.2 The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.

6.3 The definition of “Controller” includes “Business Operator” as defined under Applicable Data Protection Law.

6.4 The definition of “Processor” includes a business operator entrusted by the Business Operator with the handling of Controller Data in whole or in part (also a “trustee”), as described under Applicable Data Protection Law. As a trustee, Processor will ensure that the use of the Controller Data is securely controlled.

Singapore

7.1 The definition of “Applicable Data Protection Law” includes the Personal Data Protection Act 2012 (PDPA).

Switzerland

8.1 The definition of “Applicable Data Protection Law” includes the Swiss Federal Act on Data Protection.

United Kingdom (UK):

9.1 References in this Addendum to GDPR will to that extent be deemed to be references to the corresponding laws of the United Kingdom (including the UK GDPR and Data Protection Act 2018).

9.2 Notwithstanding anything to the contrary in this Addendum or in the Agreement (including, without limitation, either party’s indemnification obligations), neither party will be responsible for any UK GDPR fines issued or levied under Article 83 of the UK GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the UK GDPR.

© 2026 BeeMatch.AI