Data processing addendum

Contents
  1. 1. Definitions and Interpretation
  2. 2. Scope and Roles
  3. 3. Duration
  4. 4. Instructions
  5. 5. Obligations and Warranties of the Customer
  6. 6. Obligations of the Company
  7. 7. Subprocessors
  8. 8. Data Subject Requests
  9. 9. Assistance
  10. 10. Security Incidents
  11. 11. Audits
  12. 12. International Transfers
  13. 13. Return and Deletion
  14. 14. Liability
  15. 15. General
  16. Schedule 1 — Description of the Processing
  17. Schedule 2 — Technical and Organisational Measures
  18. Schedule 3 — Subprocessors

Version 24 September 2026

This Data Processing Addendum ("DPA") forms part of the Agreement between Pallarium, a prototype service run before incorporation by its founder (the "Company"), and the Customer. It is accepted by the Customer on acceptance of the Terms, and applies from the first use of the Save Function by or on behalf of the Customer, without further signature. Until the company is incorporated, the Company is the founder of Pallarium, acting for the company to be incorporated, as provided in Section 3.9 of the Terms; on incorporation, this DPA and every right and obligation under it are assumed by Pallarium in accordance with that Section.

1. Definitions and Interpretation

1.1 In this DPA the following terms have the following meanings. Capitalised terms not defined here have the meanings given in the Agreement.

  • "Account" means a user account on the Service, identified by an email address.
  • "Agreement" means the Terms and the Incorporated Documents, any Order and any other agreement between the Company and the Customer governing the use of the Service, together with this DPA.
  • "Aggregated Information" means information that does not identify, and cannot reasonably be used to identify, the Customer, any Authorised User or any other natural person.
  • "Alternative Transfer Mechanism" means a mechanism, other than the SCCs, that permits the lawful transfer of Personal Data to a third country under Applicable Data Protection Law, including the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, where the Company is certified under it.
  • "Applicable Data Protection Law" means all laws and regulations relating to the processing of Personal Data that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, EU Data Protection Law, UK Data Protection Law, Swiss Data Protection Law, the CCPA and the Kazakhstan Law.
  • "Authorised User" means a natural person who accesses the Service through an Account of the Customer.
  • "CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, and its implementing regulations.
  • "Contact Email" means [CONTACT EMAIL = hello@pallarium.com].
  • "Controller", "Processor", "Data Subject", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR, and "Process" and "Processed" are construed accordingly. "Controller" includes a "business" and "Processor" includes a "service provider" within the meaning of the CCPA, and, for the purposes of the Kazakhstan Law, "Controller" includes an "owner" and an "operator" and "Processor" includes a "third party" processing Personal Data on their behalf.
  • "Customer" means the natural or legal person that has accepted the Terms and on whose behalf an Account is used, including an individual acting in a business or professional capacity on his or her own behalf.
  • "Customer Content" has the meaning given in the Terms.
  • "Customer Personal Data" means Personal Data contained in Customer Content that the Company Processes on behalf of the Customer in the provision of the Service, including Personal Data contained in Saved Calculations, other than Customer Content stored under a Test Account.
  • "Documented Instructions" has the meaning given in Section 4.1.
  • "EU Data Protection Law" means the GDPR and the laws of the Member States of the European Economic Area implementing or supplementing it.
  • "GDPR" means Regulation (EU) 2016/679.
  • "Kazakhstan Law" means the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 "On Personal Data and their Protection".
  • "Personal Data" means any information relating to an identified or identifiable natural person, and includes "personal information" and "personal data" as defined in Applicable Data Protection Law.
  • "Privacy Policy" means the Company's Privacy Policy published on the Site.
  • "Production Database" means the database from which the Service operates.
  • "Prohibited Data" has the meaning given in Section 5.3.
  • "Retention Schedule" means the Company's Retention Schedule published on the Site.
  • "Sanctions Policy" means the Company's Sanctions and Export Compliance Policy published on the Site.
  • "Save Function" means the function of the Service by which an Authorised User stores a calculation in the Service.
  • "Saved Calculation" means the input values, results and document parameters of a calculation stored by an Authorised User by use of the Save Function, together with any well, field or file label stored with them.
  • "SCCs" means the standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • "Security Incident" means a breach of security of the Service leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Service" has the meaning given in the Terms.
  • "Site" means the website at pallarium.com, its subdomains and any successor or additional domain operated by the Company for the Service.
  • "Subprocessor" means a third party engaged by the Company to Process Customer Personal Data.
  • "Subprocessor List" means the Company's list of Subprocessors published on the Site.
  • "Swiss Data Protection Law" means the Swiss Federal Act on Data Protection and its implementing ordinances.
  • "Terms" means the Company's Master Terms of Service published on the Site.
  • "Test Account" means an Account issued by the Company for testing or demonstration whose email address is on a domain of the Company.
  • "Trade Control Laws" means "Sanctions" and "Export Control Laws" as defined in the Terms.
  • "UK Addendum" means the international data transfer addendum to the SCCs issued by the Information Commissioner of the United Kingdom, as in force from time to time.
  • "UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 of the United Kingdom.

1.2 Headings are for convenience only. "Including" does not limit the words that precede it. References to a statute or regulation are to it as amended, consolidated or replaced.

2. Scope and Roles

2.1 This DPA applies to the Processing of Customer Personal Data by the Company in the provision of the Service, to the extent that such Processing is subject to Applicable Data Protection Law.

2.2 The Customer is the Controller, or a Processor acting on behalf of a third-party Controller, of Customer Personal Data. Save as provided in Section 6.6, the Company is a Processor, or a Subprocessor, of Customer Personal Data.

2.3 The Company is the Controller of Account Data, Security Data, Activity Records, Measurement Data, Consent Records, Server Log Data, service fault records, Correspondence Data, Billing Data, Compliance Data and the other categories of Personal Data described in, and as those terms are defined in, the Privacy Policy. This DPA does not apply to that Processing, and does not restrict the Company in that capacity. An Activity Record relating to a Saved Calculation identifies the Saved Calculation by an identifier only and contains no Customer Content.

2.4 Where the Customer acts as Processor on behalf of a third-party Controller, the Customer warrants on a continuing basis that the third-party Controller has authorised the Documented Instructions, the engagement of the Company and the engagement of the Subprocessors, and the Customer shall pass to the third-party Controller, without undue delay, every notice given by the Company under this DPA. Save as required by Applicable Data Protection Law or the SCCs, the Company has no obligation towards any third-party Controller.

2.5 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Schedule 1.

2.6 This DPA does not apply to Customer Content stored under a Test Account. In respect of a Test Account the Company is the Customer and the Controller.

3. Duration

3.1 This DPA remains in force for as long as the Company Processes Customer Personal Data, and terminates on the completion of the deletion described in Section 13, without prejudice to the provisions of this DPA that by their nature survive termination.

4. Instructions

4.1 The Company Processes Customer Personal Data only on the documented instructions of the Customer ("Documented Instructions"). The Agreement, this DPA and the use of the functions of the Service by Authorised Users, including the storage, retrieval and deletion of Saved Calculations and the deletion of an Account, constitute the Customer's complete Documented Instructions at the time of acceptance of this DPA. The Customer instructs the Company to Process Customer Personal Data for the purposes set out in Section 6.4.

4.2 Any further instruction shall be given in writing to the Contact Email, is binding on the Company only if the Company agrees to it in writing, and may be made subject to the payment of the Company's reasonable costs. The Company is not obliged to modify the Service to give effect to any instruction.

4.3 The Company shall inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the Processing concerned until the instruction is confirmed, modified or withdrawn. The Company is not obliged to review instructions for legal compliance, and its failure to inform the Customer does not constitute acceptance of the lawfulness of an instruction.

4.4 The Company may Process Customer Personal Data otherwise than on Documented Instructions where required to do so by law to which it is subject. In that case the Company informs the Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest. Where that law is not the law of the European Union or of a Member State, and the SCCs apply, Clauses 14 and 15 of the SCCs govern the Company's obligations.

4.5 The Customer is solely responsible for determining whether the Service is appropriate for the Processing of Customer Personal Data, and the Company is not responsible for monitoring the Customer's compliance with Applicable Data Protection Law.

5. Obligations and Warranties of the Customer

5.1 The Customer warrants, represents and undertakes on a continuing basis that:

(a) it has, and will maintain, a lawful basis for the Processing of Customer Personal Data by the Company under the Agreement;

(b) it has provided all notices to, and obtained all consents and authorisations from, Data Subjects and other persons that are required for the Processing;

(c) its instructions comply with Applicable Data Protection Law;

(d) it has all rights necessary to store Customer Content in the Service, including rights under any licence, terms of use or statutory restriction applicable to data obtained from public registers, data providers or other third parties, and the storage of Customer Content in the Service does not infringe any such right or restriction; and

(e) Customer Content contains only such Personal Data as is necessary for the Customer's purposes.

5.2 The Customer shall not include in Customer Content any Personal Data other than the names of operators, fields and wells to the extent that such names identify a natural person, and shall not use labels or other free-text fields of Customer Content to record Personal Data.

5.3 The Customer shall not store in the Service: (a) special categories of personal data within the meaning of Article 9 of the GDPR; (b) Personal Data relating to criminal convictions and offences; (c) Personal Data of children; (d) government identification numbers, payment card data, bank account data, health data, biometric data or precise geolocation data of natural persons; (e) "sensitive personal information" within the meaning of the CCPA; or (f) any Personal Data which Applicable Data Protection Law requires to be stored in, or prohibits from being transferred out of, a particular territory, including Personal Data that the Kazakhstan Law requires to be stored in a database or digital object located in the territory of the Republic of Kazakhstan, unless the Customer has satisfied that requirement independently of the Service (together, "Prohibited Data"). The Company has no obligation in respect of Prohibited Data, and may delete Prohibited Data on becoming aware of it.

5.4 The Customer is responsible for the acts and omissions of its Authorised Users, for the security of the credentials and mailboxes of its Authorised Users, and for ending sessions and deleting Accounts of persons who are no longer authorised by it.

5.5 The Service is not a backup or archiving service. The Customer is responsible for keeping its own copies of Customer Content.

5.6 The Customer shall defend, indemnify and hold harmless the Company, its officers, directors, employees and agents against all claims, losses, fines, penalties, damages, costs and expenses (including reasonable legal fees) arising out of or in connection with any breach of this Section 5, any instruction of the Customer, or any Processing carried out in accordance with the Documented Instructions.

6. Obligations of the Company

6.1 The Company shall Process Customer Personal Data only in accordance with the Documented Instructions and for the purposes set out in Schedule 1.

6.2 The Company shall ensure that persons authorised by it to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and have access only to the extent necessary for their duties.

6.3 The Company shall implement the technical and organisational measures set out in Schedule 2. The Customer acknowledges that those measures are subject to technical progress and development, and that the Company may modify them from time to time, provided that the modification does not materially decrease the overall level of security of the Service. The Customer has assessed those measures and agrees that they provide a level of security appropriate to the risk of the Processing.

6.4 The Company and its personnel access Customer Content only:

(a) to provide the Service;

(b) to provide support requested by the Customer or an Authorised User;

(c) to prevent, detect, investigate and remedy Security Incidents, faults and abuse of the Service;

(d) to perform backups and restorations;

(e) where required by law, subject to Section 4.4;

(f) to establish, exercise or defend legal claims and to investigate breaches of the Agreement; and

(g) to screen persons, wells, fields and projects identified in Customer Content, and to restrict, suspend or refuse the Service, as provided in the Sanctions Policy.

6.5 The Company shall not sell or share Customer Personal Data; retain, use or disclose it for any purpose other than the business purposes specified in this DPA, including any commercial purpose other than providing the Service; retain, use or disclose it outside the direct business relationship between the Company and the Customer; or combine it with Personal Data that the Company receives from or on behalf of another person or collects from its own interactions with the Data Subject, except as permitted by Applicable Data Protection Law. The Company certifies that it understands and will comply with the restrictions in this Section 6.5, and shall inform the Customer if it determines that it can no longer meet its obligations under the CCPA; in that case the Customer may take reasonable and appropriate steps to stop and remediate unauthorised Processing.

6.6 To the extent that the Company Processes Customer Personal Data for the purposes in Section 6.4(f), it does so as a Controller of that Processing, on the basis of its legitimate interest in establishing, exercising and defending legal claims and in enforcing the Agreement, and only to the extent necessary for those purposes. The Company informs the Customer of such Processing, save where the law prohibits it or where informing the Customer would prejudice the claim or the investigation.

6.7 The Company shall not use Customer Content to train machine-learning or artificial-intelligence models, or to improve or develop the Service.

6.8 Nothing in this DPA restricts the Company from Processing information that is not Customer Personal Data, including Aggregated Information and technical information concerning the operation, performance and security of the Service.

7. Subprocessors

7.1 The Customer grants the Company a general written authorisation to engage Subprocessors. The Subprocessors engaged at the date of acceptance of this DPA are those identified in the Subprocessor List, which the Customer authorises.

7.2 The Company shall impose on each Subprocessor, by written contract, data protection obligations that provide for, in substance, the same level of protection of Customer Personal Data as this DPA. Where a Subprocessor fails to fulfil its data protection obligations, the Company remains liable to the Customer for the performance of that Subprocessor's obligations, subject to Section 14.

7.3 The Company shall give notice of any intended addition or replacement of a Subprocessor by updating the Subprocessor List and by notice under Section 15.5 at least thirty (30) days before the new Subprocessor begins Processing Customer Personal Data. Where the addition or replacement is necessary to maintain the security, integrity or availability of the Service, the Company may give shorter notice, and shall give notice as soon as practicable.

7.4 The Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notice to the Contact Email within fifteen (15) days of the Company's notice. The parties shall discuss the objection in good faith. If the objection is not resolved within thirty (30) days of its receipt, the Customer's sole and exclusive remedy is to cease use of the Save Function and to delete its Customer Content or its Account; where the Customer has prepaid fees for a period not yet elapsed, the Agreement governs any refund. Absent a timely objection, the new Subprocessor is deemed authorised.

7.5 On request the Company shall provide the Customer with the information about a Subprocessor that is necessary for the Customer to assess it, subject to confidentiality. Commercial terms may be withheld.

8. Data Subject Requests

8.1 The Service enables Authorised Users to retrieve, correct by re-saving, and delete Saved Calculations, and to delete Accounts. The Customer shall use those functions to respond to requests of Data Subjects.

8.2 Where the Company receives a request from a Data Subject concerning Customer Personal Data, the Company shall, where it can identify the Customer from the request, forward the request to the Customer without undue delay, and shall not respond to it except to direct the Data Subject to the Customer, unless required by law or instructed in writing by the Customer.

8.3 Taking into account the nature of the Processing, the Company shall provide the Customer with reasonable assistance, by appropriate technical and organisational measures and insofar as possible, in responding to requests of Data Subjects that cannot be fulfilled through the functions of the Service. The Company may charge its reasonable costs for such assistance.

9. Assistance

9.1 Taking into account the nature of the Processing and the information available to the Company, the Company shall provide the Customer with reasonable assistance in ensuring compliance with Articles 32 to 36 of the GDPR and the corresponding provisions of Applicable Data Protection Law, in the first instance by making available this DPA, the Privacy Policy, the Retention Schedule, the Subprocessor List and Schedule 2. Assistance beyond these documents may be made subject to the payment of the Company's reasonable costs.

10. Security Incidents

10.1 The Company shall notify the Customer of a Security Incident without undue delay after becoming aware of it and, where feasible, within forty-eight (48) hours. The notification is given under Section 15.5.

10.2 The notification describes, to the extent then known to the Company, the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a point of contact. Information that is not available at the time of notification is provided in phases as it becomes available.

10.3 The Company shall take reasonable steps to contain and remedy the Security Incident within its reasonable control, and shall provide the Customer with information reasonably necessary for the Customer to meet its obligations to notify Supervisory Authorities and Data Subjects.

10.4 The Customer is responsible for any notification to Supervisory Authorities, Data Subjects and other persons of a Security Incident concerning Customer Personal Data. The Company shall not notify any such person on the Customer's behalf, save where required by law or instructed in writing by the Customer.

10.5 Notification of, or response to, a Security Incident by the Company is not an acknowledgement of fault or liability. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including pings, port scans, denial-of-service attacks and unsuccessful sign-in attempts, are not Security Incidents.

11. Audits

11.1 On written request, not more than once in any twelve (12) month period, the Company shall make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, in the form of this DPA, Schedule 2, the Subprocessor List and written responses to a reasonable security questionnaire. Such information is confidential information of the Company and may be used by the Customer only to assess the Company's compliance with this DPA.

11.2 Only where the information provided under Section 11.1 is insufficient to demonstrate compliance, or where required by a Supervisory Authority or by Applicable Data Protection Law, the Customer may conduct an audit, including an inspection, subject to the following conditions: (a) at least sixty (60) days' prior written notice, unless a shorter period is required by a Supervisory Authority; (b) a scope, date and duration agreed in advance in writing, the duration not exceeding eight (8) hours; (c) conduct by the Customer or by an independent auditor that is not a competitor of the Company and that is bound by written confidentiality obligations acceptable to the Company; (d) conduct during ordinary working hours at the place of the audit without unreasonable disruption to the Company's operations; (e) no access to data of other customers, to the systems of Subprocessors or to information subject to legal privilege; (f) not more than once in any twelve (12) month period, save where a Supervisory Authority requires otherwise or following a Security Incident affecting Customer Personal Data; and (g) at the Customer's expense, including reimbursement of the Company's time at its then-current rates.

11.3 Audits of Subprocessors are satisfied by the certifications, reports and documentation that the Subprocessor makes available to the Company.

12. International Transfers

12.1 Location. Customer Content is stored on servers located in Finland, within the European Economic Area. Encrypted copies of the Production Database are held outside the production server, on equipment used exclusively by authorised personnel of the Company, located in the country the operator works from. The Company is established in the United States, and its personnel access Customer Personal Data from the United States and from the country the founder works from. The Customer authorises the Processing of Customer Personal Data in those countries and in the countries of the Subprocessors identified in the Subprocessor List.

12.2 European Economic Area. To the extent that the Processing of Customer Personal Data by the Company involves a transfer of Personal Data subject to EU Data Protection Law to a country that is not subject to an adequacy decision, and no Alternative Transfer Mechanism applies, the SCCs are incorporated into this DPA and completed as follows:

(a) Module Two applies where the Customer is a Controller, and Module Three applies where the Customer is a Processor; the Customer is the "data exporter" and the Company is the "data importer";

(b) Clause 7 (docking clause) does not apply;

(c) in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 7.3;

(d) in Clause 11, the optional language does not apply;

(e) in Clause 13, the competent supervisory authority is determined in accordance with Clause 13 and Annex I.C;

(f) in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;

(g) in Clause 18(b), disputes are resolved before the courts of Ireland;

(h) Annex I.A is completed by the details of the parties in the Agreement; Annex I.B by Schedule 1; Annex I.C by Clause 13; Annex II by Schedule 2; and Annex III by the Subprocessor List; and

(i) by accepting this DPA, each party is deemed to have signed the SCCs as of the date of acceptance.

12.3 United Kingdom. To the extent that the Processing involves a transfer of Personal Data subject to UK Data Protection Law to a country that is not subject to adequacy regulations, and no Alternative Transfer Mechanism applies, the SCCs apply as set out in Section 12.2, as amended by the UK Addendum, which is incorporated into this DPA. Table 1 of the UK Addendum is completed by the details of the parties in the Agreement; Table 2 by Section 12.2; Table 3 by Schedules 1 and 2 and the Subprocessor List; and in Table 4 either party may end the UK Addendum.

12.4 Switzerland. To the extent that the Processing involves a transfer of Personal Data subject to Swiss Data Protection Law to a country not recognised as providing adequate protection, the SCCs apply as set out in Section 12.2 with the following modifications: references to the GDPR are to be read as references to Swiss Data Protection Law; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" includes Switzerland, so that Data Subjects in Switzerland may enforce their rights in their place of habitual residence.

12.5 Scope of the SCCs. Where the Processing of Customer Personal Data by the Company is itself subject to EU Data Protection Law or UK Data Protection Law, the SCCs and the UK Addendum apply only to the extent that a transfer mechanism is required, and are without prejudice to the obligations that apply to the Company directly. Where the European Commission or the Information Commissioner adopts clauses or another mechanism for transfers to importers whose Processing is subject to that law, the parties shall rely on them from their entry into force, and the Company may amend this Section 12 accordingly by notice.

12.6 Alternative Transfer Mechanism. Where the Company is certified under an Alternative Transfer Mechanism, transfers covered by it are made under that mechanism, and the SCCs apply only if it ceases to be valid for the transfer.

12.7 Order of precedence. In the event of conflict between the SCCs or the UK Addendum and the other provisions of the Agreement, the SCCs and the UK Addendum prevail to the extent of the conflict. Nothing in the Agreement is intended to vary or contradict the SCCs or to prejudice the fundamental rights or freedoms of Data Subjects.

12.8 Republic of Kazakhstan. Where the Kazakhstan Law applies to Customer Personal Data, the Customer is responsible for obtaining the consent of Data Subjects to the collection and Processing of their Personal Data, including its transfer to the Company and its cross-border transfer to the countries identified in Section 12.1, for the storage of that Personal Data in the territory of the Republic of Kazakhstan where required, and for any other obligation of an owner or operator under the Kazakhstan Law.

13. Return and Deletion

13.1 During the term of the Agreement, Authorised Users may retrieve and delete Customer Content through the functions of the Service. A Saved Calculation deleted by an Authorised User, and all Customer Content of an Account that is deleted, is deleted from the Production Database at once.

13.2 On the termination or expiry of a Plan, Customer Content that can be accessed only under that Plan remains available for retrieval for thirty (30) days, after which the Company deletes it, unless a Plan giving access to it is again in force. The Company may delete an Account that has not been accessed for 730 days, together with its Customer Content, after thirty (30) days' notice to its email address.

13.3 Copies of Customer Content in copies of the Production Database are deleted when those copies expire in accordance with the Retention Schedule. Until then they are not used except to restore the Service, and Customer Content deleted before a restoration is deleted again before the Service is resumed.

13.4 The Company may retain Customer Personal Data to the extent required by law, in which case it remains subject to this DPA and is Processed only for the purpose of that requirement.

13.5 On request made within thirty (30) days of deletion, the Company confirms the deletion in writing.

13.6 Retrieval of Customer Content through the functions of the Service constitutes its return. Where the Customer does not retrieve Customer Content before its deletion under this Section 13, the Customer elects its deletion. Where the Company closes an Account otherwise than at the Customer's request, it makes the Customer Content of that Account available for retrieval for thirty (30) days, save where a Trade Control Law, a court or a competent authority prohibits it. Where the Account was closed because of a threat to the security of the Service, the Company may, instead of restoring access, deliver the Customer Content to the email address of the Account in a machine-readable format on written request made within that period.

14. Liability

14.1 Each party's liability arising out of or in connection with this DPA, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability in the Agreement, and any reference in those provisions to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. This DPA does not create any separate or additional limit.

14.2 To the maximum extent permitted by Applicable Data Protection Law, the Company is not liable for any claim, loss or damage to the extent arising from the Company's Processing of Customer Personal Data in accordance with the Documented Instructions, from Prohibited Data, or from a breach by the Customer of Section 5.

14.3 Nothing in this DPA limits the liability of either party towards Data Subjects under the SCCs or under Applicable Data Protection Law where such limitation is not permitted by law. Where a party pays compensation to a Data Subject that corresponds in whole or in part to the responsibility of the other party, it may recover from the other party that part of the compensation.

15. General

15.1 Precedence. In the event of conflict relating to the Processing of Customer Personal Data, the following order of precedence applies: (a) the SCCs and the UK Addendum, where applicable; (b) this DPA; (c) the other documents of the Agreement. This order applies in accordance with Section 2.3(a) of the Terms and notwithstanding any statement of precedence in any other document of the Agreement, including the Sanctions Policy.

15.2 Amendment. The Company may amend this DPA by publishing an amended version on the Site. Amendments required by law, by a decision of a Supervisory Authority or court, or by a change in Subprocessors under Section 7, and amendments that do not materially reduce the protection of Customer Personal Data, take effect on publication. Other amendments take effect thirty (30) days after notice under Section 15.5; continued use of the Save Function after that date constitutes acceptance.

15.3 Governing law and jurisdiction. Save as provided in Section 12 for the SCCs and the UK Addendum, this DPA is governed by the law that governs the Agreement under Section 34 of the Terms, and disputes arising out of or in connection with it are resolved in accordance with Sections 35 to 37 of the Terms.

15.4 Severability. If any provision of this DPA is held invalid or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions remain in full force. Where a provision cannot be so modified, it is severed without affecting the remainder.

15.5 Notices. Notices under this DPA are given in accordance with Section 38 of the Terms. Notices to the Company are given by email to the Contact Email. Notices to the Customer are given by email to the email address of any Account of the Customer or of its administrator, or by notice in the Account.

15.6 No third-party rights. Save as provided in the SCCs, no person other than the parties has any right to enforce any term of this DPA.

Schedule 1 — Description of the Processing

1. Parties. Data exporter: the Customer, as identified in the Agreement; role: Controller or Processor. Data importer: the Company, as identified in the preamble; role: Processor or Subprocessor. Contact: the Contact Email.

2. Subject matter. The storage and making available of Customer Content in the Service.

3. Nature of the Processing. Storage, retrieval, display, transmission to the Authorised User's browser, backup, restoration, screening under the Sanctions Policy and deletion.

4. Purposes. To store Saved Calculations and make them available to the Customer and its Authorised Users through the Service; to maintain copies for restoration; to provide support requested by the Customer; to maintain the security of the Service; the other purposes set out in Section 6.4.

5. Categories of Data Subjects. Authorised Users; and any natural person whose Personal Data the Customer or its Authorised Users include in Customer Content, including persons named in well, lease, field or file labels.

6. Categories of Personal Data. Identifiers and names contained in labels and other fields of Customer Content, and the association of Customer Content with the Account that stored it. The content of Customer Content is determined solely by the Customer and its Authorised Users.

7. Sensitive data. None. The storage of Prohibited Data is not permitted (Section 5.3).

8. Frequency of transfer. Continuous, as Authorised Users store and retrieve Customer Content.

9. Duration and retention. For the term of the Agreement and until deletion under Section 13; copies of the Production Database in accordance with the Retention Schedule.

10. Location. Storage in Finland; encrypted copies in the country the operator works from; access by the Company's personnel from the United States and from the country the founder works from.

11. Transfers to Subprocessors. As identified in the Subprocessor List, for the purposes and in the locations stated in it.

12. Competent supervisory authority. As determined under Clause 13 of the SCCs.

Schedule 2 — Technical and Organisational Measures

1. Hosting and physical security. The Service runs on a server located in a data centre in Finland, within the European Economic Area, operated by the hosting provider identified in the Subprocessor List, which is responsible for physical access control, power, cooling and network resilience of the data centre under its data processing agreement with the Company.

2. Encryption in transit. All connections to the public Service use TLS; requests made without encryption are redirected, and HTTP Strict Transport Security is applied. Service Communications are transmitted to the mail provider over TLS.

3. Isolation of the page. The pages of the Service are served with a content security policy that prohibits the loading of resources from, and connections to, any origin other than the Service itself. Local Files are read within the Authorised User's browser and are not transmitted to the Company.

4. Authentication. Sign-in is by single-use codes sent to the Account email address, stored only as hashes, valid for fifteen minutes, limited to five attempts and valid only in the browser that requested them; and, optionally, by password, stored only as a salted scrypt hash. Session identifiers are stored by the server only as hashes. Session cookies are HttpOnly and SameSite=Strict, and Secure on the public Service. Sessions expire after thirty days without use and after ninety days in any case. Authorised Users can end all sessions at once; setting, changing or removing a password ends all other sessions.

5. Abuse prevention and monitoring. Requests for codes, sign-in attempts and notices are limited per email address, per browser and per truncated network address, with temporary lockouts. Counters are kept under keyed hashes of email addresses. Authorised Users are notified by email of sign-ins from browsers or devices not previously used with the Account and of any setting, change or removal of a password, and can view the record of sign-ins in the Account.

6. Application environment. The application runs in a container with a read-only root file system, under an unprivileged user and with privilege escalation disabled. The database is held on a separate volume, with file permissions restricted to the owner.

7. Administrative access. Administrative functions are not exposed on the public Service. They are available only on a separate, password-protected environment, to authorised personnel. Access to the server is restricted to authorised personnel. The administrative functions do not display the content of Saved Calculations.

8. Minimisation and separation. IP addresses are truncated by the web server before access log entries are written, and the application receives only truncated addresses. Measurement Data is stored without any key that links it to an Account. Customer Content is associated with the Account that stored it and is not combined with other data. Activity Records refer to Saved Calculations by identifier only.

9. Availability and resilience. The Production Database is copied nightly on the production server; each copy is checked for integrity before it is kept, is stored with owner-only permissions, and is retained for fourteen days. Copies of the Production Database held outside the production server are encrypted before they leave it, are held on equipment used exclusively by authorised personnel of the Company, located in the country the operator works from, and are deleted not later than thirty days after they were taken. No unencrypted copy of the Production Database is held outside the production server, save a copy decrypted to verify or carry out a restoration, which is deleted within twenty-four hours.

10. Deletion. Deletion of an Account removes all data stored under it from the Production Database in a single transaction. A deletion routine runs daily and removes records whose retention period has ended.

11. Change management. Changes to the Service are released only after automated checks, and a point of rollback is kept for each release.

12. Personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations and are granted access on a need-to-know basis.

13. Incident response. The Company detects, contains, assesses, notifies and records Security Incidents in accordance with Section 10, and keeps a written record of each personal data breach, its effects and the remedial action taken.

Schedule 3 — Subprocessors

The Subprocessors authorised under Section 7.1 are those identified in the Subprocessor List as Processing Customer Content.