Data Processing Addendum

Atbash Data Processing Addendum

Legal

Data Processing Addendum

Atbash Technologies Ltd. — forms part of the Atbash Platform Terms of Use

1.INCORPORATION AND SCOPE

1.1

Agreement. This Data Processing Addendum (this “DPA”), forms part of the Atbash Platform Terms of Use or separately executed services agreement governing the Services (the “Agreement”) between Atbash Technologies Ltd. (“Atbash”), and the entity identified as Customer in the Agreement (“Customer”). This DPA governs Processing of Customer Personal Data by or on behalf of Atbash in providing the Services. Capitalized terms not defined here have the meanings given in the Agreement.

1.2

Effectiveness. This DPA takes effect when incorporated into an Agreement accepted through its electronic acceptance mechanism or an Order, or when separately executed by the Parties. Acceptance of the incorporating Agreement constitutes acceptance of this DPA. No separate signature is required, except where required to complete a transfer instrument or Affiliate accession. Atbash will make the applicable DPA available with the incorporating Agreement. This DPA continues for as long as Atbash or its Sub-processors retain Customer Personal Data.

1.3

Defined scope. This DPA does not expand the subscribed Services or grant access to an unsupported feature, Deployment Mode or data category. Its protections apply to Customer Personal Data actually Processed by or on behalf of Atbash, including Personal Data submitted contrary to the Agreement; such submission does not authorize additional Processing or excuse either Party's applicable obligations.

1.4

Any capitalized term that is not defined in this document has the same meaning as it does in the main Agreement.

2.DEFINITIONS AND DATA CLASSIFICATION

2.1

Applicable Data Protection Laws” mean the privacy, data protection and data security laws and binding regulations applicable to a Party's Processing under this DPA, as amended or replaced, including, where applicable: Regulation (EU) 2016/679 (EU GDPR); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinances (Swiss FADP); and applicable U.S. state comprehensive privacy laws and their implementing regulations (U.S. Privacy Laws). A law applies only to the extent its territorial, substantive and other applicability requirements are met. Nonbinding guidance does not independently expand the Parties' contractual obligations.

2.2

Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject” and “Supervisory Authority” have the meanings given under Applicable Data Protection Law or, where no corresponding definition applies, the EU GDPR. These terms include equivalent concepts, including personal information, consumer, business, service provider and contractor, where applicable. References to a Processor include a Sub-processor where the context requires.

2.3

Customer Personal Data” means Personal Data contained in Customer Data or Customer Records, or otherwise generated or collected by the Services, that Atbash Processes on behalf of Customer in providing the Services. It includes Personal Data in Submitted Actions, Decision Inputs, Policies, tool arguments, Customer-provided context, Agent or workflow metadata, Decisions, approval records and relevant Service Data. It excludes only Processing properly falling within Section 3.3 and information that does not constitute Personal Data under Applicable Data Protection Laws. This definition supplements, and does not alter ownership of, Customer Data, Customer Records or Atbash Technology under the Agreement.

2.4

Audit Data” means Customer-specific records generated by the Services concerning Submitted Actions, Decisions, Policies and their versions, Agent identities, Operator activity and associated integrity, provenance and judgment metadata. Audit Data is Customer Records for purposes of the Agreement, to the extent it falls within that definition.

2.5

On-Chain Audit Data” means the subset of Audit Data recorded in, or represented by information on, a blockchain or distributed ledger, including relevant payloads, state, event records and transaction metadata. An off-chain record is not itself On-Chain Audit Data merely because a ledger references it; the reference is On-Chain Audit Data.

2.6

Service Data” means technical, operational, security, diagnostic and performance telemetry generated through operation of the Services. Usage Data remains the narrower category defined in the Agreement and excludes substantive Actions, Policies, Decision Inputs and Customer Records. Service Data does not reclassify substantive Customer content as Usage Data. A record may be both Audit Data and Service Data. Its treatment depends on the Personal Data it contains and the purpose and role of the relevant Processing, not the label or contractual ownership of the record.

2.7

Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed by Atbash or a Subprocessor. Unsuccessful attempts that do not compromise Customer Personal Data are not Personal Data Breaches.

2.8

Subprocessor” means a person engaged by Atbash, directly or through another Subprocessor, to Process Customer Personal Data on Customer's behalf in performing Atbash's obligations under the Agreement. It includes an Atbash Affiliate or evaluation provider performing that role, but excludes Atbash personnel and a Customer Recipient acting outside that chain.

2.9

Customer Recipient” means a Third-Party Product provider, Customer-hosted endpoint or other recipient to which Customer specifically directs a disclosure outside Atbash's Subprocessor chain.

2.10

Restricted Transfer” means a transfer of Customer Personal Data requiring an appropriate transfer safeguard under Applicable Data Protection Law because it is not covered by an applicable adequacy decision or regulation. It includes remote access and onward disclosure where those activities constitute a regulated transfer.

3.ROLES AND THE ATBASH CONTROL BOUNDARY

3.1

Roles. Customer acts as Controller where it determines the purposes and essential means of Processing Customer Personal Data, and as Processor where it acts on another Controller's behalf. Atbash acts respectively as Customer's Processor or Subprocessor and, where applicable, its service provider or contractor. Where Customer is a Processor, Customer warrants that it has and will maintain all authorizations necessary to appoint Atbash, issue instructions, authorize Subprocessors and permit the transfers contemplated by this DPA. Customer will communicate the relevant Controller’s instructions to Atbash and promptly forward Atbash’s relevant notices and information to that Controller.

3.2

Control allocation. ustomer is responsible for the lawfulness of its underlying workflows and Processing instructions, the Personal Data it submits, and its selection and configuration of Agents, Policies, Decision Inputs and integrations. Atbash is responsible for its Processing of Customer Personal Data and the Processing entrusted to its Subprocessors, as provided in this DPA and Applicable Data Protection Law. The Atbash Control Boundary governs the allocation of operational responsibilities; deployment location alone does not alter that allocation. Subject to this DPA, Atbash may determine the non-essential technical and organizational means of providing the Services. Neither that discretion nor Atbash’s evaluation of Submitted Actions and generation of Decisions, in itself, makes Atbash a Controller or joint Controller of Customer Personal Data.

3.3

Independent Processing. Atbash acts as an independent Controller to the extent it lawfully Processes Personal Data for its own independent purposes rather than on Customer’s behalf. Such Processing falls outside this DPA and is subject to Applicable Data Protection Law and that Privacy Notice.

3.4

Data Classification. Contractual ownership or designation of information as Service Data, Audit Data or Atbash Technology does not, by itself, exclude that information from Customer Personal Data. Pseudonymized, hashed or otherwise cryptographically represented information remains subject to this DPA to the extent it constitutes Personal Data Processed on Customer’s behalf.

4.INSTRUCTIONS AND PERMITTED PROCESSING

4.1

Documented instructions. Customer instructs Atbash to Process Customer Personal Data for the limited purposes in Annex 1, as implemented through the Agreement, this DPA, applicable Orders and Product Schedules, supported configurations selected by authorized Customer personnel, and documented support requests within the Services' agreed scope. These instructions include necessary receipt, evaluation, transmission, recording, security, maintenance and support activities. General rights to administer or improve the Services, exercise contractual rights, use Feedback or collect Usage Data do not authorize unrelated Processing of Customer Personal Data.

4.2

Purpose limitation. Atbash will Process Customer Personal Data only on those documented instructions, including as necessary to provide, secure, maintain and support the subscribed Services, or as otherwise specifically authorized by this DPA consistently with Applicable Data Protection Law. Atbash will not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for targeted advertising, or retain, use or disclose it in a manner inconsistent with its applicable Processor, service provider or contractor obligations.

4.3

Legally required Processing. Atbash may Process Customer Personal Data where required by law to which it is subject, subject to mandatory restrictions on disclosure and transfers. Where Article 28(3)(a) EU GDPR applies, the exception to Customer instructions is limited to Union or Member State law as that Article requires.

4.4

Unlawful or additional instructions. Atbash will immediately inform Customer if, in Atbash's opinion, an instruction infringes Applicable Data Protection Law, unless legally prohibited. Atbash may suspend the affected Processing, while protecting retained data, pending clarification or a lawful alternative. Atbash is not required to provide legal advice or independently investigate the legal sufficiency of Customer's business purposes. Instructions requiring material changes beyond the agreed Services require written agreement on scope, feasibility and reasonable charges; this does not condition Atbash's existing statutory or contractual duties on a further agreement. If a lawful resolution cannot reasonably be achieved, the affected Services may be suspended or terminated under the Agreement or the applicable transfer instrument.

4.5

Statistics. Atbash may generate and use aggregated or de-identified statistics.

5.CUSTOMER OBLIGATIONS

5.1

Lawfulness. Customer represents and undertakes that it has and will maintain the rights, lawful bases, required notices, consents and authorizations necessary to provide Customer Personal Data and instruct its Processing under this DPA. Customer will ensure that its instructions comply with Applicable Data Protection Law and its duties to any upstream Controller. Customer remains responsible for determining whether an underlying Agent workflow involves regulated automated decision-making, employee monitoring, sensitive-data Processing or other heightened requirements, and for the required notices, assessments and human oversight.

5.2

Minimization and configuration. Customer will limit Personal Data in Submitted Actions, Decision Inputs, Policies and related fields to what is reasonably necessary for the supported purpose; configure Agents, Integrations, endpoints and access rights accordingly; and use available minimization features appropriately. Customer will not intentionally submit unnecessary sensitive data or place Personal Data in fields prohibited by the Documentation. Atbash may apply supported redaction and minimization before transmission or recording.

5.3

Sensitive and regulated information. Customer represents and warrants that it will not submit sensitive or special-category Personal Data under Applicable Data Protection Law, including (without limitation) financial information, health information, biometric identifiers or government-issued identification numbers, as Customer Data, whether in Decision Inputs, Agent metadata or otherwise, unless an Order expressly authorizes the relevant categories and use case. Any authorization is subject to the specified safeguards and any required additional agreement, including an effective business associate agreement where applicable. Authorization to submit such information does not authorize its recording on-chain. The Agreement’s restrictions on unsupported data, classified information and other specially regulated data remain applicable. Customer is responsible for ensuring that each authorized submission has the required lawful basis, notices, consents and other authorizations. Submission contrary to this Section does not expand Atbash’s permitted Processing purposes or subscribed obligations. Atbash’s mandatory protection obligations continue to apply to Customer Personal Data it actually Processes.

5.4

Cooperation and contacts. Customer will maintain a current privacy or security contact and authorized administrative contacts, promptly supply information reasonably needed to implement lawful instructions or investigate an incident, and protect Customer-controlled credentials and endpoints. Customer will use available self-service functions to address requests where reasonably sufficient. These duties do not transfer Atbash's Processor obligations to Customer.

6.JUDGES AND CUSTOMER RECIPIENTS

6.1

Providers appointed by Atbash. A Judge, model provider, security engine or other provider appointed by Atbash to Process Customer Personal Data on Atbash's behalf is a Subprocessor and is subject to Section 7; provided, however, that in Customer selects it from a menu of Atbash-managed options or generates it internally, then Atbash will be absolved from liability for Customer configurations.

6.2

Separate Customer relationships. Where Customer independently obtains a provider and directs the Services to transmit data under Customer's account, credentials and separate arrangement, the provider's role depends on the actual relationship: it may be Customer's separate Processor or Subprocessor, or an independent Controller. Customer is responsible for the separate arrangement and for authorizing its disclosure, including any required transfer safeguard. Atbash will disclose only the information reasonably necessary for the documented instruction and only to the authorized endpoint.

6.3

Transmission boundary. For a lawful, authorized disclosure to a Customer Recipient outside Atbash's Subprocessor chain, Atbash's responsibility for that recipient's subsequent Processing ends upon completion of the directed transmission. Atbash remains responsible for its connector, transmission, credential handling and all copies or resulting Customer Personal Data it retains or receives, and for any breach independently attributable to Atbash.

6.4

Customer endpoints and fallback. Customer operates and secures Customer-hosted and custom endpoints, except for functions expressly undertaken by Atbash. Atbash will not send Customer Personal Data to an alternative Customer Recipient without Customer authorization. Atbash-managed fallback providers remain subject to the Subprocessor requirements.

7.Subprocessors

Customer authorizes Atbash to engage Subprocessors to perform the Processing described in this DPA.

8.SECURITY AND PERSONNEL

8.1

Security measures. Atbash will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access, and otherwise meet its obligations under Article 32 EU GDPR and corresponding Applicable Data Protection Law.

8.2

Personnel. Atbash will ensure that persons it authorizes to Process Customer Personal Data are bound by contractual or appropriate statutory confidentiality obligations and have access only as reasonably necessary for their roles. Atbash will ensure that such persons Process Customer Personal Data only as authorized by Atbash's lawful instructions, unless applicable law requires otherwise.

8.3

Changes and testing. Atbash may update its technical and organizational measures without materially decreasing the overall security of the Services or impairing compliance with this DPA. This DPA does not grant Customer an unrestricted right to scan, penetrate or test Atbash's systems; Section 11 governs verification. It does not represent that Atbash holds a particular certification, uses a specified cryptographic standard or offers an unsupported key-management feature.

9.PERSONAL DATA BREACHES

9.1

Notice. Atbash will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to Customer's designated security contact or, if none is designated, its account administrator through an appropriate direct channel.

9.2

Information and response. Taking account of information reasonably available, Atbash will describe the nature of the breach, affected categories and approximate numbers of Data Subjects and records where ascertainable, likely consequences, measures taken or proposed to contain and remediate it, and a contact for further information. Atbash may provide information in phases without undue further delay. Atbash will take appropriate steps to investigate, contain and remediate the breach and provide reasonable assistance with Customer's legally required notifications and mitigation.

9.3

Communications and protected information. Customer is responsible for determining and making notifications required of it or its upstream Controller. Atbash may make disclosures required of Atbash by law and will coordinate where legally permitted and practicable. Atbash need not waive privilege or disclose other customers' information or details that would materially compromise security, but will provide relevant nonprivileged factual information through a reasonably protective alternative where needed for compliance. Atbash is not required to take actions outside its reasonable control. Notification or assistance does not constitute an admission of fault or liability.

10.INDIVIDUAL RIGHTS AND COMPLIANCE

10.1

Data Subject requests. Atbash will promptly notify Customer of a request it receives to exercise rights concerning identifiable Customer Personal Data, unless legally prohibited, and may redirect the requester to Customer.

10.2

Assessments and consultation. Taking account of the nature of Processing and information available to it, Atbash will reasonably assist Customer with security-of-processing duties, data protection impact assessments, transfer assessments, prior consultation and other legally required assessments relating to Atbash's Processing. Assistance includes relevant available information about data flows, recipients, safeguards and ledger limitations. Atbash does not undertake to conduct Customer's assessment, select its lawful basis, provide legal advice or assume Controller duties.

10.3

Costs. Atbash may charge reasonable fees for unusually burdensome, repetitive or bespoke assistance beyond those ordinary obligations, after providing an estimate.

11.DEMONSTRATING COMPLIANCE AND AUDITS

11.1

Compliance Information. Atbash will make available information necessary to demonstrate compliance with its applicable Processor obligations. Customer shall first use Atbash’s available standard compliance materials, which may include security documentation, assessment summaries, completed questionnaires and any relevant certifications or independent reports. Requests for supplementary information must identify the specific compliance requirement and material information gap. Atbash may respond through existing documentation, written responses or another reasonably sufficient means.

11.2

Audit Procedure. Where the information provided under Section 11.1 is insufficient to satisfy Customer’s verification obligations under Applicable Data Protection Law, the Customer shall provide reasonable advance written notice specifying the legal basis, scope, proposed procedures and proposed auditor and the Parties shall mutually agree on the coordination of the audit’s scope, timing, duration and safeguards in advance. Audits shall occur no more than once in any twelve-month period. Remote review shall be used where reasonably sufficient; any onsite inspection shall occur during normal business hours and minimize disruption to Atbash’s operations.

11.3

Audit Safeguards. Customer may conduct the audit itself or appoint a suitably qualified independent auditor. Atbash may reasonably object to an external auditor that is a direct competitor, lacks appropriate qualifications or independence, or presents a material confidentiality or security risk, in which case Customer shall appoint a suitable replacement or conduct the audit itself. Customer and its auditor shall comply with Atbash’s reasonable access, security and confidentiality requirements. Audit access shall be limited to information and systems relevant to the authorized scope and shall not expose other customers’ information or require disclosure of privileged material. Atbash may provide redacted evidence, supervised access or equivalent verification to protect confidential information, intellectual property and system security. Penetration testing, vulnerability scanning, source-code access and other intrusive testing require Atbash’s prior written agreement on scope and safeguards.

11.4

Costs and Findings. Notwithstanding Section 10.3, Customer shall bear its own audit and auditor expenses and reimburse Atbash’s reasonable, proportionate costs of facilitating an audit under Section 11.2, disclosed in advance. Customer shall promptly provide Atbash with the findings and a reasonable opportunity to respond before finalizing any report. Atbash will remediate substantiated noncompliance for which it is responsible within a period appropriate to the applicable legal requirement and risk. An adverse finding does not automatically require Atbash to reimburse Customer’s audit expenses; any claim for recovery remains subject to the Agreement. Compliance materials, audit evidence and findings constitute Atbash Confidential Information and may be used solely to assess compliance, exercise rights under the Agreement or satisfy applicable legal requirements.

12.GOVERNMENT REQUESTS

12.1

Legal Process. Atbash may disclose Customer Personal Data in response to legally binding governmental, regulatory or judicial process, subject to Applicable Data Protection Law. To the extent legally permitted, Atbash will promptly notify Customer and may direct the requesting authority to Customer. Atbash will assess the request’s validity and limit disclosure to the information legally required. Customer is responsible for determining whether to seek a protective order or other relief on its own behalf.

12.2

Challenges and Cooperation. Except as required by Applicable Data Protection Law or an applicable transfer instrument, Atbash retains discretion whether to challenge a request, seek protective measures or pursue an appeal, taking account of available legal grounds, prospects of success, cost and operational impact. Where the SCCs apply, Atbash will comply with their government-access requirements, including Clause 15. Atbash will provide reasonable cooperation with Customer’s lawful efforts to obtain relief. Atbash is not required to waive privilege, violate a legal prohibition or follow Customer instructions that conflict with binding legal requirements.

13.INTERNATIONAL TRANSFERS

13.1

Processing Locations. Customer authorizes Atbash and its authorized Subprocessors to Process Customer Personal Data in the countries identified in Annex 1, the Subprocessor List and any applicable Product Schedule. Atbash may select and change Processing locations subject to this DPA’s applicable notice, Subprocessor and transfer requirements. No hosting, residency or localization restriction applies unless expressly agreed in an Order or this DPA. Selection of a hosting region does not, by itself, restrict support access, evaluation providers, telemetry Processing or ledger replication.

13.2

Transfer Mechanisms. Atbash will implement the transfer mechanism and supplementary safeguards required for Restricted Transfers for which it is responsible. Customer shall provide the information, authorizations and reasonable cooperation necessary to complete and maintain the applicable transfer arrangements. Customer-directed disclosures to Customer Recipients remain subject to this DPA. Atbash may adopt a replacement lawful transfer mechanism in accordance with this DPA without obtaining separate Customer consent where such consent is not legally required.

14.RETENTION, RETURN, DELETION AND IMMUTABLE RECORDS

14.1

Retention During the Services. Customer instructs Atbash to retain and Process Customer Personal Data for the purposes and periods specified in this DPA and any applicable Agreement. Customer shall use the available retention, export, correction and deletion functions to administer its data. Requests that cannot be fulfilled through those functions shall be handled under Section 10. Atbash is not required to develop Customer-specific functionality or support a retention configuration not included in the Services, subject to its existing obligations under this DPA.

14.2

End of Services. Upon completion of the affected Services, Atbash will, at Customer’s choice, return or delete the affected Customer Personal Data and delete remaining copies, subject to this DPA. Return may be effected by making the data available through Atbash’s standard export functionality or another reasonably usable format. Customer is responsible for requesting and completing any export within the export period agreed upon the parties. If Customer does not elect return within that period, Customer instructs Atbash to delete the data. Atbash will complete deletion and provide confirmation where required by Applicable Data Protection Law or this DPA. Atbash has no obligation to provide indefinite post-termination access, reconstruct data lawfully deleted under this Section or create a bespoke export format. Following expiration of the disclosed export period, Atbash may proceed with the instructed deletion without further notice.

14.3

Backups and Required Retention. Customer Personal Data contained in backups or disaster-recovery copies may remain until deleted or overwritten through the documented backup cycle, to the extent deferred deletion is legally permitted. Pending deletion, Atbash will continue to protect the data, restrict it from ordinary access and active use, and reapply outstanding deletion instructions before any restored data is returned to active Processing. Atbash may also retain Customer Personal Data to the extent and for the period required by applicable law, subject to this DPA.

14.4

Audit and Independent Records. Audit Data may be retained for the audit, security and evidentiary purposes and periods expressly agreed upon by the Parties Any continuing audit-retention service after termination must be covered by a documented Customer instruction and agreed retention period. Otherwise, Audit Data containing Customer Personal Data is subject to Section 14.2.

14.5

Immutable Records. Customer acknowledges that entries recorded on an immutable or append-only ledger may not be capable of modification or deletion, including following termination. The applicable architecture and limitations shall be specified in the Annexes attached to this DPA. Atbash does not undertake to rewrite ledger history or remove entries where the documented architecture technically prevents that action. For permitted ledger Processing, Atbash will apply the measures specified in the attached Annexes to implement applicable rights requests, including, as appropriate, correction or deletion of mutable records and identifying links within its control and restriction of further Processing. Deletion of off-chain information constitutes erasure or anonymization of surviving ledger information only where technically effective and legally sufficient. Residual ledger records may be retained only where they no longer constitute Personal Data or their retention is otherwise lawful.

14.6

Ledger Authorization and Customer Restrictions. Customer shall not include Customer Personal Data in Customer-controlled content it submits or designates for on-chain recording, or instruct Atbash to record such data on-chain. Customer shall review and minimize that content and configure its Agents and integrations accordingly. Permitted Personal Data recording requires a supported design, a completed Annex identifying the applicable data, recipients, purposes, retention and safeguards, and a lawful Customer instruction consistent with that specification. Atbash may decline an instruction or restrict or suspend the affected feature where it reasonably determines that the proposed or continuing Processing would violate Applicable Data Protection Law, this DPA or the documented restrictions. Availability of any alternative architecture or recording mode is encouraged and such conduct resides solely with the Customer.

14.7

Prohibited Submissions and Remediation. Customer remains responsible, in its applicable role, for the lawfulness of its submissions and instructions and for determining or obtaining the relevant Controller’s instructions concerning Data Subject requests. If Customer breaches the submission restrictions in this DPA, Atbash may reject further submissions or restrict or suspend the affected Processing and require Customer’s reasonable cooperation in remediation. Customer shall reimburse Atbash’s reasonable, documented remediation costs to the extent caused by Customer’s breach, excluding costs attributable to Atbash’s breach of the Agreement. These rights supplement Atbash’s applicable suspension, termination and other remedies under the Agreement.

15.LIABILITY

15.1

Contractual Liability. Atbash’s liability arising out of or relating to this DPA or the Processing of Customer Personal Data is subject to the exclusions, limitations and aggregate liability caps in the Agreement, regardless of the form of action or legal theory asserted. Those protections apply to claims concerning confidentiality, security, unauthorized Processing or disclosure, loss or corruption of data, retention, deletion, international transfers and the acts or omissions of Subprocessors. Claims under the Agreement and this DPA share the applicable aggregate limit and do not give rise to separate or cumulative caps. Customer’s liabilities and indemnification obligations remain governed by the Agreement.

15.2

Customer-Controlled Risks. As between the Parties, Customer is responsible for losses, claims and expenses to the extent caused by: (a) Customer’s failure to establish a lawful basis, provide required notices, obtain required consents or authorizations, or secure instructions from an upstream Controller; (b) unlawful, inaccurate, incomplete or unauthorized Customer instructions, or Customer’s selection or configuration of Agents, Policies, Decision Inputs, access permissions or integrations; (c) submission of sensitive or otherwise restricted Personal Data contrary to the Agreement, this DPA or the applicable Order; (d) inclusion of Personal Data in Customer-controlled content submitted or designated for on-chain recording contrary to Section 14.6; (e) the operation or security of Customer Systems, Customer-controlled credentials or endpoints, or subsequent Processing by Customer Recipients outside Atbash’s Subprocessor chain; or (f) Customer’s failure to use available controls or act on a specific notice from Atbash identifying a material risk within Customer’s control. Atbash shall not be liable to Customer to the extent a loss is caused by those matters. This allocation does not exclude liability to the extent caused by Atbash’s breach of the Agreement or a failure in Processing for which Atbash is responsible under this DPA.

15.3

Customer Commitments to Third Parties. Atbash is not bound by, and assumes no responsibility for, privacy notices, contractual undertakings, service levels, indemnities or representations made by Customer to its Affiliates, customers, Data Subjects or other third parties unless Atbash expressly accepts the relevant obligation in a signed agreement. Customer shall not represent that Atbash provides security, deletion, localization, retention or other protections exceeding its express commitments. Any additional liability resulting from Customer’s commitments shall remain Customer’s responsibility, without limiting obligations imposed directly on Atbash by applicable law.

15.4

Customer Indemnification. Customer’s indemnification obligations under the Agreement apply to third-party claims arising from the matters identified in Section 15.2 to the extent covered by that indemnity. Such claims include claims concerning unauthorized disclosure, prohibited sensitive-data submissions, unlawful on-chain recording and Customer’s failure to obtain the rights or authorizations necessary for the instructed Processing. The Agreement’s indemnification procedures, exclusions and applicable liability treatment govern those claims.

15.5

Mitigation and Recovery. Customer shall take reasonable steps within its control to prevent and mitigate losses and promptly provide information reasonably required to investigate and address an affected Processing activity. Atbash shall not be responsible for avoidable increases in loss to the extent caused by Customer’s unreasonable failure to take those steps. Customer may not bind Atbash to a settlement, admission or third-party expenditure without Atbash’s prior written consent. This does not prevent Customer from taking legally required action or reasonable urgent mitigation measures; any resulting claim for reimbursement remains subject to the Agreement. Incident notification, cooperation or voluntary assistance by Atbash does not constitute an admission of liability, an agreement to reimburse expenses or a waiver of contractual protections.

15.6

Fines and Duplicate Recovery. No regulatory fine, penalty, settlement, investigation expense or third-party payment is automatically recoverable from Atbash merely because it concerns Customer Personal Data or the Services. Recovery requires an applicable legal or contractual entitlement and remains subject to the Agreement and any legal restriction on reimbursement or indemnification. Customer and its Affiliates shall not obtain duplicate recovery for the same loss.

15.7

Affiliates. Customer warrants that it has authority to enter this DPA and issue instructions on behalf of Affiliates using the Services under its Agreement. Customer shall ensure their compliance with the applicable terms and is responsible for their acts and omissions as if they were Customer’s own. Customer shall coordinate their notices, instructions, assistance requests, audits and contractual claims through a single administrative contact.

16.PRECEDENCE, ADMINISTRATION AND CHANGES

16.1

Contract Structure and Precedence. This DPA forms part of the Agreement and controls a conflict solely to the extent the conflict concerns Processing of Customer Personal Data. The Agreement continues to govern commercial matters, fees, remedies and liability as provided in Section 15. An Order or negotiated addendum modifies this DPA only to the extent it expressly identifies the modification and is signed by authorized representatives of both Parties. No purchase order, supplier-portal submission, onboarding form, Customer privacy policy or other Customer procurement document modifies this DPA merely because Atbash acknowledges or signs it, provides Services or accepts payment in connection with it.

16.2

Amendments. Atbash may amend this DPA by publishing an updated version and notifying Customer in accordance with the Agreement’s amendment procedure. An amendment will take effect as specified in the notice and that procedure; no separate signature is required where the Agreement permits electronic amendment. No amendment will materially reduce the overall protection of Customer Personal Data during the then-current Subscription Term. Changes to Subprocessors, security measures and transfer instruments remain subject to their respective provisions. Any different amendment procedure expressly agreed in a signed addendum shall govern that addendum.

16.3

Administration and Notices. Customer shall maintain current administrative, privacy and security contact details. Atbash may rely on the details most recently supplied by Customer. Routine operational notices may be delivered electronically, including through the Services. Personal Data Breach notices, Subprocessor-change notices and other notices requiring direct delivery shall be sent by email or another agreed direct channel. The Agreement’s governing law, dispute-resolution and general administrative provisions apply to this DPA. Provisions necessary to protect retained Customer Personal Data survive for the applicable retention period. Except as provided in Section 16.4 or an applicable Affiliate accession, this DPA creates no independent third-party beneficiary rights.

16.4

Optional Separate Execution. This DPA is binding through incorporation into the Agreement and does not require separate execution unless expressly required by an applicable transfer instrument. If separately executed, each signatory represents that it is authorized to bind the identified Party. Separate execution does not amend the Agreement’s effective date, fees, liability allocation or other commercial terms.

16.5

Annexes. All annexes and schedules attached to this DPA and/or an applicable Order, shall form an integral part thereof.

Schedules and Annexes

Annex 1: Details of Processing

This Annex describes the Processing authorized by the Parties and subject to the DPA. The actual scope is limited by the Services purchased, Customer's lawful instructions and enabled Deployment Mode. The categories below describe possible content and do not imply that Atbash requires or receives every category. An Order may narrow or supplement these details consistently with the DPA.

Processing elementAgreed description
Subject matterOperation of Customer's subscribed agent authorization, evaluation, runtime control, approval and audit functionality, together with associated support, maintenance and security.
DurationThe period in which the affected Services are provided and the limited period needed to complete return or deletion, plus any specifically instructed continuing retention service or retention required by law under Section 14.
NatureReceipt and evaluation of Submitted Actions and available Decision Inputs against Customer-selected Policies; generation and communication of Decisions; routing of human review; implementation of supported controls; generation, retrieval and export of relevant records; support and service security.
Specified purposesAuthenticate and associate Agents and authorized personnel with the correct Customer environment; assess proposed Actions against applicable Policies; route and implement supported authorization outcomes; enable Customer review and approvals; evidence the applicable authorization, Policy version and provenance; diagnose faults and maintain the confidentiality, integrity and availability of the Services; answer documented support requests; and produce permitted minimized statistics under Section 4.5.
Processing operationsCollection, transmission, recording, organization, structuring, consultation, retrieval, evaluation, comparison with Policies, generation of outputs, storage, permitted disclosure, minimization, restriction, rectification, export, erasure and destruction. Ledger recording is included only to the extent expressly authorized under the completed Annex 5.
FrequencyRepeated or continuous transfers as Customer submits or generates relevant information through the Services; occasional transfers for onboarding, configuration, support and exports.
Data SubjectsDepending on the use: Customer personnel, contractors, Authorized Users, Operators and approvers; Agent developers and administrators; Customer customers, users and patients; suppliers, recipients and counterparties; and other individuals referenced in submitted workflows. An Agent is not itself a natural person, but its identifiers or records may relate to identifiable people.
Identity and administration dataNames, business contact information, account or role identifiers, organization associations, permissions and relevant authentication metadata, to the extent Processed on Customer's behalf. Agent and Operator public identifiers may be Personal Data where linkable to an individual. Private keys and authentication secrets are subject to the separate key-handling boundary and designated secure interfaces.
Workflow contentProposed Actions; tool names and arguments; Policies and Policy versions; Decision Inputs; operational or factual context; target systems and resources; recipients and counterparties; and other Customer-provided information relevant to the evaluation. These fields may contain Personal Data about individuals beyond Customer personnel.
Generated recordsDecisions and other documented outcomes; evaluation inputs and outputs; reasons, confidence values, provider and performance metadata; judgment and tool-call identifiers; timestamps; Agent associations; HOLD records; Operator approvals, rejections and related authorization history; and Customer-specific audit records and reports.
Technical informationRelevant usage, connection, request, device or network identifiers, access and diagnostic records, error information, performance metrics and security telemetry to the extent actually collected and Processed on Customer's behalf. Exact collection and independent-purpose boundaries must be completed under OI-02 and OI-03.
Sensitive dataNo sensitive category is inherently required for general operation. Where lawfully included in a supported workflow, content may contain special categories under Article 9 EU GDPR, criminal-offence data under Article 10, health or financial information, government identifiers or other sensitive information under applicable law. Intentionally enabled categories and additional safeguards must be specified below; unsupported sector-specific data remains restricted under the Agreement.

Sensitive-data specification. For an enabled category, the Processing is limited to the specified purpose, authorized recipients and necessary personnel, with minimization, appropriate access restrictions and the additional measures recorded in Annex 2 and the Order. Customer supplies the required legal basis and any Article 9 condition or Article 10 authorization. Unexpected submission does not expand the authorized purpose. Personal Data about children, where present, requires the applicable supported use and legally required authorizations and protections, and its existence should be notified in advance.