STANDARD CONTRACTUAL CLAUSES PACKAGE

FOR INTERNATIONAL TRANSFERS OF PERSONAL DATA

Orakul
Effective date: 21 September 2026

This Standard Contractual Clauses Package ("SCC Package") supplements the Data
Processing Agreement ("DPA") and the applicable End User License Agreement,
Terms of Use, order form, invoice, quotation, purchase confirmation,
implementation agreement or other agreement governing the use of Orakul
(the "Agreement").

This SCC Package applies where and to the extent that Personal Data protected by
the GDPR, the UK GDPR, Swiss data protection law or other applicable data
protection laws is transferred internationally in connection with Orakul and such
transfer requires appropriate contractual safeguards.

This SCC Package is intended to incorporate:

(a) for transfers subject to Regulation (EU) 2016/679 ("GDPR"), the Standard
Contractual Clauses adopted by the European Commission in Commission
Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs");

(b) for transfers subject to the UK GDPR, the UK International Data Transfer
Addendum to the EU Commission Standard Contractual Clauses issued by the UK
Information Commissioner's Office under section 119A of the Data Protection
Act 2018 ("UK Addendum"); and

(c) for transfers subject to Swiss data protection law, the adaptations set out
in this SCC Package for the purposes of the Swiss Federal Act on Data
Protection ("Swiss FADP").

This SCC Package does not replace the full text of the EU SCCs or the UK
Addendum where mandatory law requires their execution or incorporation in full.
The full text of the EU SCCs and UK Addendum is incorporated by reference as set
out below.

1. PARTIES

1.1 Data Exporter

The "data exporter" is the Customer, Licensee or other entity or individual that
uses Orakul and transfers or makes available Personal Data from the EEA, United
Kingdom, Switzerland or another protected jurisdiction.

The data exporter is identified in the applicable Agreement, order form,
invoice, purchase confirmation, account registration, correspondence or other
commercial document between the Parties.

1.2 Data Importer

The "data importer" is:

Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia
Taxpayer / Registration No.: 304589032
Legal address: 19/3 Rustavi Highway, Tbilisi, Georgia
E-mail for notices: max@orakul.digital

Role: Service Provider / Processor, where Maksim Safianov processes Personal
Data on behalf of the Customer in connection with Orakul support,
implementation, maintenance, diagnostics, activation, telemetry, logs or other
services.

1.3 Product

The relevant product is Orakul.

2. RELATIONSHIP WITH THE DPA AND AGREEMENT

2.1 This SCC Package forms part of the DPA and the Agreement.

2.2 In the event of a conflict between this SCC Package and the DPA or
Agreement, this SCC Package prevails to the extent required by applicable data
protection law for the relevant international transfer.

2.3 In the event of a conflict between this SCC Package and the EU SCCs or UK
Addendum, the mandatory provisions of the EU SCCs or UK Addendum prevail.

2.4 Capitalised terms not defined in this SCC Package have the meanings given
to them in the DPA, the Agreement, the GDPR or the EU SCCs, as applicable.

3. TRANSFER SCENARIOS AND SCC MODULES

3.1 Transfers involving Orakul as Processor

Where the Customer is a Controller and Maksim Safianov / Orakul processes
Personal Data on behalf of the Customer as Processor, the Parties agree that
Module Two of the EU SCCs applies:

Controller-to-Processor transfer: Module Two.

3.2 Transfers involving Orakul as Sub-Processor

Where the Customer acts as Processor for its own client and Maksim Safianov /
Orakul processes Personal Data as the Customer's Sub-Processor, the Parties
agree that Module Three of the EU SCCs applies:

Processor-to-Processor transfer: Module Three.

3.3 Other transfer scenarios

If another transfer scenario applies, the Parties will cooperate in good faith
to enter into the appropriate SCC module or another lawful transfer mechanism.

3.4 Customer-controlled AI providers and integrations

The Parties acknowledge that Orakul may enable the Customer to transmit content
and Personal Data to third-party AI providers and integrations selected,
configured and authorised by the Customer, including providers such as OpenAI,
Anthropic Claude, Google Gemini, OpenRouter, Google Workspace, Bitrix24,
Yandex Metrica, Yandex Webmaster and Yandex Disk.

Unless Maksim Safianov / Orakul separately determines the purposes and means of
such processing, these providers are not sub-processors of Maksim Safianov /
Orakul. They are providers, processors, sub-processors or independent
controllers engaged by the Customer under the Customer's own accounts,
credentials, API keys, tokens, settings and instructions.

The Customer is solely responsible for:

(a) assessing whether the use of such providers and integrations is lawful;

(b) selecting the appropriate provider, region, model, service settings and
data retention settings;

(c) entering into any required data processing terms with those providers;

(d) identifying those providers as its own processors or sub-processors where
required;

(e) implementing any required transfer mechanism, including SCCs, UK Addendum,
Swiss safeguards or other lawful mechanism; and

(f) informing data subjects and obtaining any required consents or other legal
bases.

4. INCORPORATION OF EU SCCs

4.1 The Parties incorporate by reference the EU SCCs adopted by Commission
Implementing Decision (EU) 2021/914 of 4 June 2021.

4.2 The incorporated EU SCCs apply as follows:

(a) Module Two applies where the Customer is the Controller and Orakul is the
Processor;

(b) Module Three applies where the Customer is a Processor and Orakul is the
Sub-Processor;

(c) Clause 7, the optional docking clause, applies;

(d) Clause 9, Option 2, general written authorisation, applies with a prior
notice period of thirty (30) calendar days for changes to sub-processors,
unless a shorter period is reasonably necessary for security, continuity,
emergency replacement or compliance reasons;

(e) Clause 11(a), optional language, does not apply;

(f) Clause 17, governing law, is the law of Ireland for transfers subject to the
GDPR, unless another EU Member State law is required by mandatory law or
expressly agreed in writing;

(g) Clause 18(b), choice of forum and jurisdiction, refers to the courts of
Ireland for transfers subject to the GDPR, unless another EU Member State
forum is required by mandatory law or expressly agreed in writing.

4.3 The Annexes to the EU SCCs are completed by the information set out in
Sections 8, 9 and 10 of this SCC Package.

5. UK INTERNATIONAL DATA TRANSFER ADDENDUM

5.1 Where a transfer is subject to the UK GDPR, the Parties incorporate the UK
International Data Transfer Addendum to the EU Commission Standard Contractual
Clauses issued by the UK Information Commissioner's Office under section 119A of
the Data Protection Act 2018, as revised from time to time.

5.2 For the purposes of the UK Addendum:

(a) the "Addendum EU SCCs" are the EU SCCs incorporated under this SCC Package;

(b) Table 1 is completed with the Party details in Section 1 of this SCC
Package;

(c) Table 2 is completed by reference to the modules and clauses selected in
Sections 3 and 4 of this SCC Package;

(d) Table 3 is completed by the information in Sections 8, 9 and 10 of this SCC
Package;

(e) Table 4: either Party may end the UK Addendum in accordance with Section 19
of the UK Addendum where permitted.

5.3 In the context of the UK Addendum, references to the GDPR are interpreted
as references to the UK GDPR, and references to EU or Member State law are
interpreted as references to the laws of England and Wales, unless otherwise
required by applicable law.

6. SWISS TRANSFERS

6.1 Where a transfer is subject to the Swiss FADP, the EU SCCs incorporated by
this SCC Package apply with the following adaptations:

(a) references to the GDPR are interpreted to include the Swiss FADP;

(b) references to the "Union", "EU" and "Member State" are interpreted to
include Switzerland where required;

(c) references to a "supervisory authority" include the Swiss Federal Data
Protection and Information Commissioner ("FDPIC");

(d) references to "personal data" include "personal data" as defined under the
Swiss FADP;

(e) references to "sensitive data" include sensitive personal data and
personality profiles or high-risk profiling to the extent protected under
Swiss law;

(f) data subjects in Switzerland may enforce their rights under the EU SCCs as
third-party beneficiaries where applicable.

6.2 For Swiss transfers, the governing law and forum provisions in the EU SCCs
will be interpreted to allow data subjects to bring claims in Switzerland where
required by mandatory Swiss law.

7. TRANSFER IMPACT ASSESSMENT AND LOCAL LAW ASSESSMENT

7.1 The Parties acknowledge that, before transferring Personal Data under the EU
SCCs, UK Addendum or Swiss adaptations, the data exporter is responsible for
assessing whether the laws and practices of the destination country may affect
the effectiveness of the applicable safeguards.

7.2 The data importer will provide reasonable information and assistance
reasonably necessary for the data exporter to complete its transfer impact
assessment, taking into account the nature of the processing and information
available to the data importer.

7.3 As of the effective date of this SCC Package, the data importer is located
in Georgia.

7.4 The Parties acknowledge that Georgia may not be treated as an adequate
jurisdiction for all purposes under all applicable data protection regimes.
Where required, the Parties rely on the SCCs, UK Addendum, Swiss adaptations or
another lawful transfer mechanism.

7.5 The Customer is responsible for conducting separate transfer assessments for
third-party AI providers, cloud services, analytics providers, CRM systems,
backup destinations and other integrations that the Customer selects and
configures through Orakul, including transfers to the United States, Russia or
other third countries.

  1. ANNEX I TO THE EU SCCs
    A. LIST OF PARTIES

A.1 Data Exporter

Name:
The Customer, Licensee or other entity or individual identified in the
Agreement, order form, invoice, quotation, purchase confirmation, account
registration, correspondence or other commercial document.

Address:
As specified by the Customer in the applicable commercial document, account
registration, correspondence or billing information.

Contact person's name, position and contact details:
As specified by the Customer, or the Customer's account, billing, technical or
legal contact.

Activities relevant to the data transferred under these Clauses:
Use of Orakul, including installation, configuration, activation, support,
maintenance, implementation, diagnostics, troubleshooting, log review,
telemetry, hosting or other services, depending on the deployment and services
ordered by the Customer.

Signature and date:
The data exporter is deemed to sign these Clauses on the date it accepts the
DPA, the Agreement, an order form, an invoice, a purchase confirmation or
otherwise uses Orakul in a manner requiring application of these Clauses.

Role:
Controller, unless the Customer processes Personal Data on behalf of a third
party, in which case the Customer may act as Processor.

A.2 Data Importer

Name:
Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia.

Address:
19/3 Rustavi Highway, Tbilisi, Georgia.

Taxpayer / Registration No.:
304589032.

Contact person's name, position and contact details:
Maksim Safianov
Individual Entrepreneur / Service Provider
E-mail: max@orakul.digital

Activities relevant to the data transferred under these Clauses:
Provision of Orakul-related services, including licensing, activation, account
administration, support, maintenance, implementation, diagnostics,
troubleshooting, log review, telemetry, security, billing, compliance and
related communications.

Signature and date:
The data importer is deemed to sign these Clauses on the effective date of this
SCC Package or on the date of the applicable Agreement, order form, invoice,
purchase confirmation or DPA, whichever is later.

Role:
Processor, or Sub-Processor where the Customer acts as Processor for a third
party.

B. DESCRIPTION OF TRANSFER

B.1 Categories of data subjects

Depending on the Customer's use of Orakul, Personal Data may relate to:

(a) Customer's employees, contractors, consultants, founders, managers,
authorised users and administrators;

(b) Customer's clients, leads, prospects, counterparties, suppliers and business
contacts;

(c) users of Customer's websites, products, services, advertising accounts,
analytics systems, CRM systems and communication channels;

(d) senders and recipients of emails, calendar participants and document
collaborators processed through connected Google Workspace accounts or other
integrations;

(e) individuals whose data is included in prompts, chat histories, knowledge
base documents, web pages, CRM records, analytics reports, logs, backups or
other content submitted to or processed through Orakul;

(f) other individuals whose Personal Data is provided by or on behalf of the
Customer.

B.2 Categories of personal data transferred

Depending on the Customer's use of Orakul, Personal Data may include:

(a) identification data, such as names, usernames, job titles, company names,
account IDs and user IDs;

(b) contact data, such as email addresses, telephone numbers, messaging
identifiers, postal addresses and social media handles;

(c) business data, such as CRM records, lead data, customer notes, commercial
correspondence, deal data, invoices, order data and support tickets;

(d) authentication and technical data, such as API keys, tokens, connection
settings, IP addresses, device data, browser data, logs, error reports and
configuration data;

(e) content data, such as prompts, chat messages, documents, knowledge base
materials, uploaded files, web page text, extracted page content, email
content, calendar data, Drive files and other Customer-controlled content;

(f) analytics and marketing data, such as website metrics, Yandex Metrica data,
Yandex Webmaster data, search data, campaign data, click data, event data
and performance reports;

(g) backup data, including database dumps and application data stored in
Customer-configured backup destinations such as Yandex Disk;

(h) billing and administrative data, such as billing contacts, payment status,
invoices, purchase history and tax information;

(i) any other Personal Data that the Customer submits, connects, authorises or
makes available through Orakul.

B.3 Sensitive data transferred

The Parties do not intend for sensitive data or special category data to be
processed by Maksim Safianov / Orakul unless the Customer chooses to submit,
connect, upload or make such data available through Orakul.

Sensitive data may include, depending on the Customer's configuration and use:

(a) special categories of personal data under Article 9 GDPR;

(b) criminal offence data under Article 10 GDPR;

(c) financial, health, biometric, genetic, political, religious, trade union,
sexual orientation or other sensitive information;

(d) confidential business information that includes Personal Data;

(e) government identifiers, identity documents or other regulated data.

Applied restrictions and safeguards:
The Customer must not submit sensitive data unless it has a valid legal basis,
has completed any required data protection impact assessment, has implemented
appropriate technical and organisational measures, and has configured Orakul and
any third-party providers appropriately. The data importer applies the technical
and organisational measures described in Annex II to the extent applicable to
its own processing.

B.4 Frequency of the transfer

Transfers may occur on a continuous, periodic, occasional or one-off basis,
depending on the Customer's installation, configuration, activation, support
requests, connected integrations, telemetry settings, backup settings and use of
Orakul.

B.5 Nature of the processing

The processing may include collection, receipt, access, transmission, storage,
hosting, retrieval, consultation, analysis, structuring, organisation,
adaptation, alteration, use, disclosure by transmission, dissemination or
otherwise making available, alignment, combination, restriction, erasure,
destruction and other operations necessary to provide Orakul and related
services.

B.6 Purpose of the processing

The purpose of the processing is to provide, operate, maintain, support, secure,
improve, troubleshoot, license, activate and administer Orakul and related
services, and to perform the Agreement and DPA.

B.7 Duration of processing and retention

Personal Data will be processed for the duration of the Agreement and thereafter
only as necessary to:

(a) provide transition, export or deletion assistance;

(b) comply with legal, tax, accounting or regulatory obligations;

(c) resolve disputes;

(d) enforce the Agreement;

(e) maintain security, audit and backup records for a limited period;

(f) fulfil any other purpose permitted by the Agreement, DPA or applicable law.

Upon termination or expiry of the Agreement, Personal Data will be deleted or
returned in accordance with the DPA, unless retention is required or permitted
by applicable law.

B.8 Transfers to sub-processors

The data importer may transfer Personal Data to authorised sub-processors as
described in Annex III and the DPA.

B.9 Customer-controlled onward transfers

Customer-controlled AI providers, integrations and backup destinations are not
treated as sub-processors of the data importer unless expressly engaged by the
data importer for its own processing activities.

These Customer-controlled providers may include, depending on Customer settings:

(a) OpenAI;

(b) Anthropic Claude;

(c) Google Gemini / Google AI services;

(d) OpenRouter;

(e) Google Workspace, including Gmail, Calendar and Drive;

(f) Bitrix24;

(g) Yandex Metrica;

(h) Yandex Webmaster;

(i) Yandex Disk backup storage;

(j) other services selected and configured by the Customer.

The Customer is responsible for the legality, transfer mechanism, disclosure,
configuration and contractual arrangements for such onward transfers.

C. COMPETENT SUPERVISORY AUTHORITY

C.1 GDPR

For transfers subject to the GDPR, the competent supervisory authority is the
supervisory authority determined under Clause 13 of the EU SCCs.

Where no other supervisory authority is clearly applicable, the Parties select
the Irish Data Protection Commission for the purposes of Clause 13, to the
extent such selection is permitted by applicable law.

C.2 UK GDPR

For transfers subject to the UK GDPR, the competent supervisory authority is the
UK Information Commissioner's Office.

C.3 Swiss FADP

For transfers subject to the Swiss FADP, the competent authority is the Swiss
Federal Data Protection and Information Commissioner.

  1. ANNEX II TO THE EU SCCs
    TECHNICAL AND ORGANISATIONAL MEASURES

The following technical and organisational measures apply to the extent relevant
to the data importer’s processing of Personal Data. The Customer remains
responsible for the security of its own environment, credentials, API keys,
tokens, infrastructure, integrations, backups, user access and configuration.

9.1 Access control

(a) Access to Personal Data is limited to persons who require access for
support, maintenance, diagnostics, billing, security, legal compliance or
other authorised purposes.

(b) Access rights are granted on a need-to-know and least-privilege basis.

(c) Administrative access is restricted and reviewed periodically where
appropriate.

(d) Authentication credentials are intended to be kept confidential and not
shared.

9.2 Credential and token handling

(a) API keys, tokens and credentials used by the Customer should be stored in
the Customer-controlled environment or configuration.

(b) The data importer does not intentionally access Customer API keys, tokens or
credentials except where necessary to provide requested support or services.

(c) The Customer is responsible for rotating, revoking and securing credentials
for AI providers, Google Workspace, Bitrix24, Yandex services and other
integrations.

9.3 Encryption and transmission security

(a) Personal Data transmitted over public networks should be protected using
TLS or comparable encryption in transit where technically feasible.

(b) The Customer is responsible for enabling HTTPS, secure transport,
encryption at rest and secure network configuration in its own deployment
environment unless those services are expressly provided by the data
importer.

(c) Backups and exports containing Personal Data should be protected using
appropriate access controls and encryption where feasible.

9.4 Logging and monitoring

(a) Logs may be used for troubleshooting, diagnostics, security, abuse
prevention and service improvement.

(b) Logs should be limited to information reasonably necessary for operational
and security purposes.

(c) The Customer should avoid including unnecessary sensitive data in logs,
prompts, support tickets or diagnostic materials.

9.5 Data minimisation

(a) The Customer should configure Orakul to transmit only the data necessary for
the relevant task, model, integration, support request or workflow.

(b) The data importer processes Personal Data only as reasonably necessary to
provide the relevant services and comply with the Agreement, DPA and
applicable law.

9.6 Support and diagnostic access

(a) The data importer may access Customer Personal Data only where access is
requested, authorised or made available by the Customer, or where necessary
to provide contracted services.

(b) Support materials, screenshots, exports, logs or files provided by the
Customer should be limited to what is necessary for the support request.

(c) The Customer should redact or anonymise Personal Data before submitting
support materials where possible.

9.7 Backups

(a) If backup functionality is configured by the Customer, backup data may
include a full dump of the Customer's database and application data.

(b) Where the Customer configures backups to Yandex Disk or another destination,
the Customer is responsible for the destination, access permissions,
retention period, encryption, transfer mechanism and legal basis.

(c) The data importer is not responsible for Customer-selected backup
destinations unless expressly agreed in writing.

9.8 Sub-processor security

(a) The data importer will use reasonable efforts to engage sub-processors that
provide appropriate technical and organisational measures.

(b) Sub-processors will be authorised and managed in accordance with the DPA and
Annex III.

9.9 Incident response

(a) The data importer will notify the Customer of a Personal Data Breach
affecting Customer Personal Data in accordance with the DPA and applicable
law.

(b) The data importer will take reasonable steps to investigate, contain and
remediate confirmed breaches within its area of responsibility.

(c) The Customer is responsible for incident response in its own environment and
with respect to Customer-controlled providers and integrations.

9.10 Availability, resilience and recovery

(a) Measures may include backups, restoration procedures, redundancy,
monitoring or other safeguards appropriate to the services actually provided
by the data importer.

(b) For self-hosted deployments, the Customer is responsible for hosting,
infrastructure, backups, disaster recovery and business continuity unless
expressly agreed otherwise.

9.11 Personnel confidentiality

Persons authorised by the data importer to process Personal Data are subject to
confidentiality obligations, whether contractual, statutory or professional.

9.12 Secure development and maintenance

Where applicable, the data importer applies reasonable measures for software
maintenance, updates, vulnerability remediation and secure handling of reported
issues.

9.13 Deletion and return

Upon termination or expiry of the Agreement, Personal Data will be deleted or
returned in accordance with the DPA, unless retention is required or permitted
by applicable law.

9.14 Customer responsibilities

The Customer is responsible for:

(a) configuring Orakul securely;

(b) selecting lawful AI providers, integrations and backup destinations;

(c) securing its servers, devices, accounts, credentials, tokens and API keys;

(d) managing user access and permissions;

(e) reviewing prompts, files, web pages and knowledge base documents before
transmission to external providers;

(f) configuring data retention and logging settings;

(g) ensuring that its use of Orakul complies with applicable data protection
laws.

  1. ANNEX III TO THE EU SCCs
    LIST OF SUB-PROCESSORS

10.1 Authorised sub-processors

The Customer gives the data importer general written authorisation to engage
sub-processors in accordance with the DPA and Clause 9 of the EU SCCs.

10.2 Current sub-processors

As of the effective date of this SCC Package, the data importer may use the
following categories of sub-processors for its own processing activities,
depending on the services used:

(a) hosting and infrastructure providers;

(b) email, communication and customer support providers;

(c) billing, accounting and payment administration providers;

(d) analytics, logging, error monitoring and telemetry providers;

(e) security, anti-abuse and compliance providers;

(f) professional advisers, accountants and legal service providers, where they
process Personal Data on behalf of the data importer.

The specific list of current sub-processors, if any, may be made available at:

https://orakul.digital/subprocessors

If this URL is not available or does not contain a current list, the Customer
may request the current sub-processor list by email at:

max@orakul.digital

10.3 Customer-controlled providers are excluded

The following providers are not sub-processors of the data importer merely
because Orakul enables integration with them or the Customer configures Orakul
to use them:

(a) AI model and routing providers selected by the Customer, including OpenAI,
Anthropic Claude, Google Gemini / Google AI services and OpenRouter;

(b) Google Workspace services connected by the Customer, including Gmail,
Calendar and Drive;

(c) Bitrix24 accounts connected by the Customer;

(d) Yandex Metrica and Yandex Webmaster accounts connected by the Customer;

(e) Yandex Disk or other storage destinations selected by the Customer for
backups;

(f) any other third-party service connected using the Customer's own account,
API key, OAuth token, credentials or configuration.

10.4 Notice of new sub-processors

The data importer will provide notice of intended changes concerning the
addition or replacement of sub-processors at least thirty (30) calendar days in
advance, unless a shorter period is reasonably necessary for security,
continuity, emergency replacement or compliance reasons.

Notice may be provided by email, through the website, customer account,
release notes, documentation or another reasonable method.

10.5 Objection

The Customer may object to a new sub-processor on reasonable data protection
grounds by notifying the data importer in writing within the notice period.

If the objection is reasonable and cannot be resolved, the Customer may
terminate the affected services in accordance with the DPA or Agreement.

11. SUPPLEMENTARY MEASURES

11.1 The Parties may apply supplementary measures where required by applicable
data protection law and reasonably appropriate to the transfer, including:

(a) encryption in transit;

(b) encryption at rest where available;

(c) pseudonymisation or anonymisation before transfer;

(d) access minimisation;

(e) strict support access procedures;

(f) credential rotation;

(g) audit logs;

(h) contractual commitments regarding government access requests;

(i) transparency reporting where available;

(j) Customer-side selection of regions, providers and retention settings.

11.2 The Customer acknowledges that the effectiveness of supplementary measures
may depend on the Customer's configuration, deployment model, provider choices
and the nature of the Personal Data submitted through Orakul.

12. GOVERNMENT ACCESS REQUESTS

12.1 The data importer will, to the extent legally permitted, notify the data
exporter if it receives a legally binding request from a public authority for
access to Personal Data transferred under the SCCs.

12.2 If legally prohibited from notifying the data exporter, the data importer
will use reasonable efforts to obtain a waiver of the prohibition where
appropriate and legally permissible.

12.3 The data importer will review the legality of any request and challenge it
where, after careful assessment, it concludes that there are reasonable grounds
to consider the request unlawful under applicable law.

12.4 The data importer will provide the minimum amount of Personal Data
reasonably necessary to comply with a legally binding request.

12.5 The data importer will document requests and responses where required by
the SCCs and applicable law.

13. AUDITS AND INFORMATION RIGHTS

13.1 The data importer will make available information reasonably necessary to
demonstrate compliance with this SCC Package, the DPA and applicable data
protection law.

13.2 Audits must be conducted in accordance with the DPA and must be limited to
what is reasonably necessary, proportionate and legally required.

13.3 The Customer must first use available documentation, security summaries,
certifications, questionnaires and written responses before requesting an
on-site or live audit.

13.4 Audits must not compromise the security, confidentiality or rights of other
customers, systems or third parties.

14. LIABILITY

14.1 The liability provisions of the Agreement and DPA apply to this SCC Package
to the maximum extent permitted by applicable law.

14.2 Nothing in this SCC Package limits liability to the extent such limitation
is prohibited by the EU SCCs, the UK Addendum, the Swiss FADP or applicable
data protection law.

15. ACCEPTANCE AND ELECTRONIC SIGNATURE

15.1 This SCC Package is entered into and accepted when the Customer:

(a) signs or accepts an Agreement, DPA, order form, invoice, quotation or
purchase confirmation that incorporates this SCC Package;

(b) clicks an acceptance button or checkbox referring to the Agreement, DPA,
SCCs or privacy terms;

(c) installs, activates, accesses or uses Orakul after being presented with or
given access to this SCC Package; or

(d) otherwise indicates acceptance by written, electronic or implied means
permitted by applicable law.

15.2 The Parties agree that electronic acceptance, click-through acceptance and
continued use may constitute valid execution of this SCC Package to the extent
permitted by applicable law.

15.3 If a wet-ink or qualified electronic signature is required by applicable
law, the Parties will cooperate in good faith to execute the required document.

16. NOTICES

Notices relating to this SCC Package must be sent to:

For the data importer:

Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia
Legal address: 19/3 Rustavi Highway, Tbilisi, Georgia
E-mail: max@orakul.digital

For the data exporter:

To the contact details provided by the Customer in the Agreement, order form,
invoice, purchase confirmation, account registration, correspondence or billing
information.

17. VERSION AND CHANGES

17.1 This SCC Package may be updated from time to time to reflect changes in
law, regulatory guidance, transfer mechanisms, Orakul functionality,
sub-processors or business operations.

17.2 Material changes will be notified by reasonable means, which may include
email, website notice, account notice, release notes or documentation update.

17.3 If a change is required by applicable law or a supervisory authority, it may
take effect immediately.

18. BANKING DETAILS FOR COMMERCIAL REFERENCE ONLY

The following details are included for commercial identification and payment
reference only and do not affect the roles or obligations under this SCC
Package:

Bank: JSC TBC Bank, Tbilisi, Georgia
SWIFT/BIC: TBCBGE22
IBAN: GE51TB7247645064400002
Beneficiary name: MAKSIM SAFIANOV
Intermediary bank (USD/EUR): Citibank N.A., New York, USA
SWIFT: CITIUS33

19. SIGNATURE BLOCK

For the data exporter:

Name:
The Customer identified in the Agreement, order form, invoice, purchase
confirmation, account registration or other commercial document.

Authorised representative:
As accepted electronically or as otherwise signed by the Customer.

Date:
Date of acceptance, signature, purchase, installation, activation or first use
of Orakul, as applicable.

Role:
Controller or Processor, as applicable.

For the data importer:

Name:
Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia

Authorised representative:
Maksim Safianov

Date:
21 September 2026

Role:
Processor or Sub-Processor, as applicable.

E-mail:
max@orakul.digital

END OF SCC PACKAGE