Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement

between UNYX AI LTD, a company incorporated in the United

Kingdom with registered office at 1 Beauchamp Court, 10 Victors Way, Barnet, Hertfordshire, United Kingdom, EN5 5TZ ("UNYX",

"Processor"), and the customer identified in the applicable order form

or agreement ("Customer", "Controller"), governing UNYX's processing

of personal data on Customer's behalf in connection with the UNYX platform

(the "Service").

Capitalised terms not defined here have the meaning given in the applicable

Master Services Agreement / Terms of Service between the parties.

1. Definitions

"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR

(the EU GDPR was incorporated into UK law by the Data Protection Act 2018).

"Data Protection Laws" means the GDPR together with any other applicable

data protection or privacy legislation in force from time to time.

"Personal Data", "Processing", "Controller", "Processor",

"Data Subject", "Sub-processor", and "Personal Data Breach" have

the meanings given in the GDPR.

"Customer Personal Data" means personal data processed by UNYX on behalf

of Customer in connection with the Service, as further described in Annex 1.

2. Roles of the Parties

2.1. As between the parties, Customer is the Controller and UNYX is the

Processor of Customer Personal Data. UNYX will process Customer Personal Data

only for the purposes described in this DPA and the underlying agreement.

2.2. Each party will comply with its respective obligations under Data

Protection Laws applicable to its role.

3. Processing of Customer Personal Data

3.1. UNYX will process Customer Personal Data only:

(a) to provide, maintain, and support the Service;

(b) on Customer's documented instructions, including as set out in the

underlying agreement and this DPA (unless required to do otherwise by law, in

which case UNYX will inform Customer before processing, unless legally

prohibited from doing so); and

(c) as further specified in Annex 1 (Details of Processing).

3.2. UNYX will promptly inform Customer if, in its opinion, an instruction

infringes Data Protection Laws.

4. Confidentiality

UNYX will ensure that personnel authorised to process Customer Personal Data

are subject to appropriate confidentiality obligations.

5. Security

5.1. UNYX will implement appropriate technical and organisational measures to

ensure a level of security appropriate to the risk, as described in Annex 3

(Security Measures).

5.2. UNYX will notify Customer without undue delay, and in any event within

72 hours of becoming aware, of any Personal Data Breach affecting Customer

Personal Data, and will provide reasonable information and cooperation to

help Customer meet their own breach notification obligations.

6. Sub-processors

6.1. Customer provides general authorisation for UNYX to engage

Sub-processors to process Customer Personal Data, subject to this Section 6.

6.2. UNYX's current list of Sub-processors is published at

https://trust.unyx.ai#sub-processors_card

(the "Sub-processor List"). Before engaging a new Sub-processor, UNYX will

update the Sub-processor List and provide notice to Customer (by publishing

the update and, where Customer has subscribed to notifications, by email) at

least 30 days in advance.

6.3. Customer may object to a new Sub-processor on reasonable data protection

grounds within 30 days of notice. If the parties cannot resolve the objection,

Customer may terminate the affected portion of the Service as its sole

remedy.

6.4. UNYX will impose data protection obligations no less protective than

this DPA on each Sub-processor, and remains liable to Customer for each

Sub-processor's performance of its obligations.

7. Data Subject Rights

UNYX will provide reasonable assistance to Customer, taking into account the

nature of the processing, to enable Customer to respond to requests from Data

Subjects to exercise their rights under Data Protection Laws. If UNYX

receives such a request directly, it will not respond (other than to confirm

receipt) without Customer's authorisation, and will forward the request to

Customer without undue delay.

8. Data Protection Impact Assessments

UNYX will provide reasonable assistance to Customer with any data protection

impact assessments, and prior consultations with supervisory authorities,

which Customer reasonably considers necessary, taking into account the nature

of the processing and information available to UNYX.

9. International Transfers

9.1. UNYX will not transfer Customer Personal Data outside the UK or European

Economic Area unless it has taken measures necessary to ensure the transfer

is compliant with Data Protection Laws, including (where applicable) by

relying on:

(a) an adequacy decision covering the recipient country; or

(b) the UK International Data Transfer Addendum / EU Standard Contractual

Clauses, which are incorporated by reference into this DPA where required.

9.2. Details of the location of processing for each Sub-processor are set out

in the Sub-processor List.

10. Audits

Upon Customer's written request, and no more than once per year (except

following a Personal Data Breach or where required by a supervisory

authority), UNYX will make available information reasonably necessary to

demonstrate compliance with this DPA, which may be satisfied by providing a

recent third-party audit report or certification. UNYX will allow for, and

contribute to, audits conducted by Customer or an auditor mandated by

Customer, subject to reasonable confidentiality and scheduling conditions.

11. Deletion or Return of Data

On termination of the Service, UNYX will, at Customer's election, delete or

return all Customer Personal Data, and delete existing copies, within

90, unless retention is required by applicable law.

12. UK GDPR / EU Representative

UNYX is incorporated in, and established in, the United Kingdom. As UNYX has

a UK establishment, no separate UK representative is required under Article

27 UK GDPR.

Where this DPA applies to processing subject to the EU GDPR, and because

UNYX has no establishment in the European Economic Area, UNYX's EU

Representative appointed under Article 27 EU GDPR is:

Guy Stiebel 
Email:
gs@unyx.ai

13. Data Protection Officer

Queries regarding this DPA or UNYX's data protection practices may be

directed to UNYX's Data Protection Officer:

Buki Ben Natandpo@unyx.ai.

14. Liability

Each party's liability arising under this DPA is subject to the limitations

and exclusions of liability set out in the underlying agreement between the

parties.

15. Precedence and Term

This DPA forms part of, and is incorporated into, the agreement between

UNYX and Customer for the Service, and takes effect for as long as UNYX

processes Customer Personal Data on Customer's behalf.

Annex 1 — Details of Processing

Subject matter: UNYX's provision of the Service to Customer.

Duration: For the term of the underlying agreement, plus the period

described in Section 11.

Nature and purpose of processing: Hosting, storage, transmission, and

processing of data submitted by or collected on behalf of Customer through

the Service, for the purpose of providing the Service's core functionality

(including account management, transaction processing, and — where enabled —

AI-assisted matching).

Categories of Data Subjects: Customer's authorised users; end customers

or counterparties of Customer whose data is submitted to the Service.

Types of Personal Data: Contact details (name, email, phone), account

credentials, transaction and account activity data, and — where applicable

and submitted by Customer — identity verification data.

Special categories of data: None processed by design; Customer should not

submit special category data unless separately agreed in writing.

Annex 2 — Sub-processors

See the current Sub-processor List at

https://trust.unyx.ai/#sub-processors_card

Annex 3 — Security Measures

UNYX maintains technical and organisational measures appropriate to the risk

of processing, including encryption in transit and at rest, access controls

and multi-factor authentication for production systems, network

segmentation, logging and monitoring, regular vulnerability scanning, an

incident response plan, and employee security training.

The current, detailed description of these measures is published and kept

up to date at UNYX's Trust Center: https://trust.unyx.ai#faq_card.