AI Transparency and Compliance Statement

Use of Artificial Intelligence in the applications of Blue Ocean Cloud Systems UG (haftungsbeschränkt)

As of: July 2026

1. What this statement is about

Our applications (including tellmi and talkmi) use Artificial Intelligence (AI) to transcribe speech, translate content and create summaries. With this statement we disclose which AI technology we use, where your data is processed and stored, and how we fulfil the obligations arising from the European AI Regulation (EU AI Act), the General Data Protection Regulation (GDPR) and the European Data Act (EU Data Act).

2. Which AI we use

We exclusively use AI models that are provided in the Microsoft Azure Cloud — and of those, only models that are hosted in data centres in Germany. In concrete terms this means: • No AI services outside the Microsoft Azure Cloud are used. • The processing of your inputs by the AI models takes place in Germany. • We do not use any models that are operated on servers outside Germany.

3. No modification of the AI models — no fine-tuning

We do not make any changes whatsoever to the AI models we use: • No fine-tuning and no training with customer data takes place. • The models themselves remain unchanged, exactly as provided by Microsoft. • We only adapt the so-called system prompt, i.e. the working instruction with which the model is configured for the respective use case (e.g. transcription or translation). Your content is therefore never used to train or further develop AI models — neither by us nor by Microsoft.

4. Confidentiality of your inputs and results

For the Azure AI services we use, Microsoft contractually guarantees that prompts (inputs) and their results (outputs): • are not shared with other customers, • are not passed on to the manufacturers of the respective models, and • are not used to train or improve the models. Your inputs thus remain within our application and the Azure environment controlled by us.

5. Data storage and encryption

All data stored with our software is stored exclusively in Germany. In addition: • All data is encrypted by Microsoft as standard (encryption of data at rest and encrypted transmission). • Beyond that, we encrypt the stored data a second time using so-called Customer Managed Keys (CMK) — i.e. with keys that we manage ourselves and that are not in the hands of the cloud provider. Your data is therefore doubly encrypted: once through Microsoft's platform encryption and once through our own keys managed by us.

6. Our role and the risk classification under the EU AI Act

We do not develop our own AI models and do not modify the models we use. We integrate commercially available AI services provided by Microsoft into our applications without modification. On this basis, we consider our role in the value chain to be that of a distributor or integrator, not that of a model provider. Regarding the risk classification: • Our applications are not intended for use in high-risk areas within the meaning of the EU AI Act (e.g. critical infrastructure, law enforcement, employee selection, credit scoring). • Our applications do not carry out any practices prohibited under the EU AI Act (no social scoring, no emotion recognition in the workplace, no biometric categorisation). • Our customers are expressly advised that they must familiarise themselves with the applicable laws of their country or of the country in which they use the software, that they must comply with those laws and that, in case of doubt, they must refrain from using our software. On this basis, we classify the risk associated with the use of our software as limited risk within the meaning of the EU AI Act.

7. Obligations under the EU AI Act — and how we fulfil them

Obligations exist even at limited risk. We fulfil them as follows: a) Transparency obligations (Art. 50 EU AI Act) Users must be able to recognise that they are working with AI and that content is AI-generated. Implementation: Our applications display a permanently visible notice on the central screens stating that the results are created with Artificial Intelligence, may contain errors and must be reviewed critically before further use. This notice is available in all 15 languages in which our applications can be operated. b) Notice on legal framework conditions (esp. for recordings) Implementation: As our applications offer recording functions, we point out in the same permanently visible place that users must comply with the applicable laws of their country or the country of use (e.g. consent requirements for recording conversations) and that, in case of doubt, use must be refrained from. c) AI literacy (Art. 4 EU AI Act) Providers and deployers must ensure that their staff have sufficient AI literacy. Implementation: The persons involved in development and operation are familiar with the functioning, capabilities and limitations of the AI services used; configurations (system prompts) are documented and versioned. d) No high-risk use / intended purpose Implementation: We market and design our applications exclusively for transcription, translation and summarisation in everyday and business contexts. Should we become aware of use in high-risk areas, we reserve the right to restrict provision. e) Monitoring and further development Implementation: We monitor the ongoing specification of the EU AI Act (including guidelines, implementing acts, labelling standards for AI content) and continuously adapt our applications and notices.

8. Obligations under the GDPR — and how we fulfil them

a) Legal basis and purpose limitation (Art. 5, 6 GDPR) We process personal data only to provide the contractually agreed services (Art. 6 (1) (b) GDPR) or on the basis of legitimate interests or consent. Details are governed by our privacy policy. b) Processing on behalf (Art. 28 GDPR) A data processing agreement is in place with Microsoft (Microsoft Products and Services Data Protection Addendum). Microsoft processes data only on documented instructions; the services we have selected are operated in Germany. c) No third-country transfers as the rule (Chapter V GDPR) By restricting ourselves to services hosted in Germany and storing data exclusively in Germany, we avoid third-country transfers in regular operation. d) Technical and organisational measures (Art. 32 GDPR) Encryption in transit and at rest, additional encryption with Customer Managed Keys, role-based access control, central sign-in with modern identity management, logging of administrative access. e) Data minimisation and storage limitation (Art. 5 GDPR) We store only the data required to provide the service. After the end of the contract or expiry of a trial period, stored content is deleted after a reasonable transition period; users can export their data beforehand. f) Data subject rights (Art. 12 et seq. GDPR) Access, rectification, erasure, restriction, data portability and objection can be asserted at any time via the contact channels stated in our privacy policy. g) No automated decision-making (Art. 22 GDPR) Our applications do not make automated decisions with legal or similarly significant effect on individuals. The AI produces work results (transcripts, translations, summaries) whose use always remains with a human being. h) Records of processing activities and notification obligations (Art. 30, 33, 34 GDPR) We maintain records of processing activities and have established processes to detect data protection incidents and report them within the statutory deadlines.

9. Obligations under the EU Data Act — and how we fulfil them

The EU Data Act strengthens in particular the rights of customers of cloud and data processing services. For us as a provider of SaaS applications this means: a) Data access and data export Customers can export the content created and stored with our software in common, structured formats and reuse it. There is no "lock-in" of content. b) Switching providers We design our contracts so that switching to another provider is not impeded by unreasonable contractual, technical or financial obstacles. After the end of the contract, we make the data available for export for a reasonable period and delete it afterwards. c) Transparency about storage location and infrastructure With this statement we disclose: processing and storage take place in the Microsoft Azure Cloud in Germany; international government access is impeded by the choice of storage location, the contractual arrangements and the additional encryption with our own keys (CMK); without our keys the data cannot be read. d) Fair contractual terms Our contractual terms do not contain any unfair clauses within the meaning of the Data Act to the detriment of our customers' data usage rights.

10. Your responsibility as a user

As much as we pay attention to quality and legal compliance — two things remain your responsibility: • Review AI results: The results created with our software are generated using Artificial Intelligence and may contain errors. Please review the results critically before using them further. • Comply with applicable law: Given the recording capabilities offered by our software, you must comply with the applicable laws of your country or of the country in which you use the software. Please inform yourself before use. If in doubt, you must refrain from using the software.

11. Contact

We are happy to answer questions about this statement, data protection or the use of AI in our applications: Blue Ocean Cloud Systems UG (haftungsbeschränkt) Grindelallee 1 20146 Hamburg Germany E-mail: info@blue-ocean.cloud This statement is reviewed regularly and updated in the event of changes to the legal situation or our services.