DATA PROCESSING AGREEMENT (DPA)

Документ доступен только на английском языке — это язык, на котором он заключается.

Orakul
Effective date: 21 September 2026

This Data Processing Agreement ("DPA") forms part of the End User License
Agreement for Orakul, the Terms of Use, order form, invoice, quotation, purchase
confirmation, implementation agreement or other agreement governing the use of
Orakul, as applicable (the "Agreement") between:

(1) Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia,
Taxpayer / Registration No. 304589032, legal address: 19/3 Rustavi Highway,
Tbilisi, Georgia ("Processor", "Service Provider", "Orakul", "we", "us"); and

(2) the customer, licensee or user that purchases, installs, accesses or uses
Orakul, or on whose behalf Orakul is used ("Controller", "Customer", "you").

Processor and Controller are each a "Party" and together the "Parties".

This DPA applies where and to the extent Processor processes Personal Data on
behalf of Controller in connection with Orakul and such processing is subject to
applicable data protection laws, including the Law of Georgia on Personal Data
Protection and, where applicable, Regulation (EU) 2016/679 ("GDPR"), the UK
GDPR and the UK Data Protection Act 2018.

This DPA is effective from the date on which Customer accepts it electronically,
signs it, incorporates it by reference into an order, or otherwise starts using
Orakul under an Agreement that refers to this DPA.

1. DEFINITIONS

1.1 "Applicable Data Protection Laws" means all data protection and privacy laws
applicable to the processing of Personal Data under this DPA, including, where
applicable, the Law of Georgia on Personal Data Protection, the GDPR, the UK
GDPR and other applicable national data protection laws.

1.2 "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data
Breach", "Processing", "Processor", "Subprocessor", "Supervisory Authority" and
"Special Categories of Personal Data" have the meanings given to them in
Applicable Data Protection Laws. Where the GDPR applies, these terms have the
meanings given in Article 4 GDPR.

1.3 "Customer Data" means data, content, documents, records, prompts, messages,
knowledge base materials, webpages, files, credentials, logs, metadata and other
information submitted to, stored in, accessed by or processed through Orakul by
or on behalf of Customer.

1.4 "Personal Data" means any Customer Data that constitutes personal data under
Applicable Data Protection Laws.

1.5 "Services" means licensing, activation, maintenance, support, diagnostics,
updates, implementation assistance and other services provided by Processor in
connection with Orakul.

1.6 "AI Provider" means a third-party artificial intelligence, large language
model, embedding, speech, text-generation, text-analysis or similar provider
selected, configured or used by Customer in connection with Orakul, including,
where applicable, providers such as OpenAI, Google Gemini, Anthropic Claude and
OpenRouter.

1.7 "Customer-Configured Integration" means any third-party system, platform,
API, account, storage, analytics service, CRM, email, calendar, cloud drive,
search console, webmaster tool, workspace account or other external service
connected to Orakul by or on behalf of Customer.

1.8 "Telemetry Data" means the limited technical and licensing data described in
Section 7 of this DPA.

2. ROLES OF THE PARTIES

2.1 Where Processor processes Personal Data on behalf of Customer in connection
with the Services, Customer is the Controller and Processor is the Processor.

2.2 Customer determines the purposes and means of processing Personal Data,
including what data is entered into Orakul, which integrations are connected,
which AI Providers are used, which prompts are submitted, which documents are
indexed or processed, which users are granted access, and where backups or
exports are stored.

2.3 Processor processes Personal Data only on documented instructions from
Customer, including instructions given through the Agreement, this DPA, the
configuration of Orakul, support requests, implementation instructions and other
documented communications.

2.4 Processor does not act as a controller of Customer Data merely because
Orakul is installed, activated or used by Customer. However, Processor may act
as an independent controller for limited business administration data, such as
accounting, invoicing, tax records, commercial communications, fraud prevention,
legal compliance and defence of legal claims.

2.5 Customer is responsible for ensuring that it has a valid legal basis for the
processing of Personal Data through Orakul, for providing required notices to
Data Subjects, for obtaining required consents where applicable, and for
responding to Data Subject requests unless the Parties agree otherwise in
writing.

3. SCOPE OF PROCESSING

3.1 Processor may process Personal Data only for the following purposes:

(a) providing licence activation and licence verification;
(b) providing updates, patches, technical maintenance and support;
(c) assisting with installation, implementation, configuration and diagnostics;
(d) troubleshooting errors, incidents and performance issues;
(e) providing security, abuse prevention and integrity of the licensing system;
(f) complying with legal obligations applicable to Processor;
(g) performing the Agreement; and
(h) other documented instructions of Customer.

3.2 The subject matter, duration, nature and purpose of processing, categories
of Data Subjects and categories of Personal Data are set out in Annex 1.

3.3 Customer acknowledges that Orakul is primarily designed as software operated
in Customer's own environment. Processor does not ordinarily host Customer's
production database, knowledge base, prompts, communications, documents or
business content unless Customer specifically provides such data to Processor
for support, implementation, diagnostics, migration, troubleshooting or other
Services.

4. CUSTOMER-CONTROLLED AI PROVIDERS

4.1 Customer acknowledges that Orakul may transmit Customer Data, including
Personal Data, prompts, messages, correspondence, knowledge base documents,
webpage text, extracted content, files, metadata and other materials, to AI
Providers selected, configured or used by Customer.

4.2 Such transmission is initiated by Customer's configuration and use of Orakul.
The relevant AI Provider is not engaged by Processor as Processor's
Subprocessor merely because Customer configures Orakul to send data to that AI
Provider using Customer's own API keys, accounts, credentials or subscriptions.

4.3 As between the Parties, AI Providers selected or configured by Customer are
Customer's own providers, processors or subprocessors, as applicable. Customer
is responsible for:

(a) reviewing the terms, privacy notices and data processing terms of each AI
Provider;
(b) entering into any required data processing agreement with such AI Provider;
(c) determining whether the AI Provider acts as Customer's processor,
subprocessor, independent controller or separate controller;
(d) ensuring a valid legal basis for transmitting Personal Data to the AI
Provider;
(e) ensuring that Data Subjects receive appropriate notices;
(f) configuring retention, training, logging and opt-out settings offered by
the AI Provider;
(g) assessing confidentiality and professional secrecy requirements;
(h) assessing whether Special Categories of Personal Data or sensitive business
data may be sent to the AI Provider; and
(i) ensuring a lawful mechanism for any international transfer, including
transfers to the United States or other third countries.

4.4 Customer acknowledges that common AI Providers may process data in the
United States or other jurisdictions outside Customer's country, the European
Economic Area, the United Kingdom or Georgia. Customer is solely responsible for
assessing and implementing any required transfer mechanism, including standard
contractual clauses, transfer risk assessments, supplementary measures or other
legally required safeguards, where Customer uses its own AI Provider account,
API key or credentials.

4.5 Processor is not responsible for the acts, omissions, security, retention
practices, model training practices, international transfers, availability,
lawfulness or compliance status of AI Providers selected, configured or used by
Customer with Customer's own accounts, API keys, credentials or subscriptions.

4.6 Processor will not intentionally redirect Customer Data to an AI Provider
other than the provider configured by Customer, except where technically
required by Customer's configuration, routing choice, model selection or
documented instruction.

5. CUSTOMER-CONFIGURED INTEGRATIONS AND EXTERNAL SERVICES

5.1 Customer may connect Orakul to Customer-Configured Integrations, including
without limitation:

(a) Google Workspace, including Gmail, Google Calendar, Google Drive and related
employee or organisational accounts;
(b) Bitrix24;
(c) Yandex Metrica;
(d) Yandex Webmaster;
(e) Yandex Disk or other cloud storage used for backups, exports or file
exchange;
(f) email, CRM, analytics, search, advertising, cloud storage, webhook,
automation, database or communication services; and
(g) any other third-party API, account, token or integration configured by
Customer.

5.2 Where Customer connects a Customer-Configured Integration, Orakul may read,
receive, transmit, export, import, synchronise, store, analyse or otherwise
process Customer Data through that integration according to Customer's settings,
permissions, tokens, API keys, OAuth grants, credentials, scripts or
instructions.

5.3 Customer-Configured Integrations are not Processor's Subprocessors merely
because Customer connects them to Orakul. As between the Parties, such providers
are selected and controlled by Customer, and Customer is responsible for
assessing and managing them under Applicable Data Protection Laws.

5.4 Customer is responsible for ensuring that the scope of permissions granted
to Customer-Configured Integrations is appropriate and lawful, including access
to employee mailboxes, calendars, drive files, CRM records, analytics accounts,
webmaster accounts, backup destinations and other third-party resources.

5.5 Without limiting the generality of this Section 5, Customer acknowledges
that if Customer configures backups, exports or database dumps to be sent to
Yandex Disk, a complete or substantial copy of Customer's database may be
transmitted to and stored in Yandex Disk under Customer's own account, token,
credentials and settings.

5.6 For Customers subject to the GDPR or UK GDPR, Customer acknowledges that use
of certain Customer-Configured Integrations, including Yandex Disk, may involve
a transfer of Personal Data to the Russian Federation or other third countries.
Customer is solely responsible for assessing the lawfulness of such transfer,
implementing any required transfer mechanism, transfer risk assessment,
supplementary measures, notices, consents or other safeguards, and determining
whether such integration may be used.

5.7 Processor is not responsible for the acts, omissions, availability,
security, retention, international transfers or compliance of
Customer-Configured Integrations selected, authorised, connected or used by
Customer.

6. PROCESSOR'S INSTRUCTIONS AND LIMITATIONS

6.1 Processor will process Personal Data only on documented instructions from
Customer unless required to do so by applicable law. In such case, Processor
will inform Customer of that legal requirement before processing, unless the law
prohibits such information on important grounds of public interest.

6.2 Processor will promptly inform Customer if, in Processor's reasonable
opinion, an instruction infringes Applicable Data Protection Laws. Processor is
not required to provide legal advice or perform a full legal assessment of
Customer's processing activities.

6.3 Processor may refuse or suspend an instruction where Processor reasonably
believes that the instruction is unlawful, creates a security risk, infringes
third-party rights, violates the Agreement, or may expose Processor to
liability.

7. TELEMETRY, LICENSING AND ACTIVATION DATA

7.1 Customer acknowledges that Orakul may transmit limited Telemetry Data to
Processor for licence activation, licence verification, fraud prevention,
security, version compatibility, support, maintenance and proof of acceptance of
legal terms.

7.2 Telemetry Data may include the following:

(a) licence key;
(b) installation domain;
(c) tariff branch or plan identifier;
(d) build identifier;
(e) software version number;
(f) user interface or control panel language;
(g) hash of the accepted EULA;
(h) hash of the accepted DPA, where DPA acceptance is enabled;
(i) date and time of EULA acceptance;
(j) date and time of DPA acceptance, where DPA acceptance is enabled;
(k) IP address of the person or system that accepted the EULA or DPA;
(l) IP address of the server request received by Processor;
(m) technical request metadata reasonably required for server logs, security,
debugging and licence verification.

7.3 Processor does not intentionally collect through Telemetry Data the content
of Customer's correspondence, knowledge base documents, prompts, webpage texts,
CRM records, email content, calendar entries, drive files, database dumps or
other Customer business content, unless such content is included by Customer in
a support request, diagnostic package, log file, screenshot or other material
submitted to Processor.

7.4 Processor will use Telemetry Data only for the purposes listed in Section
7.1 and for compliance with the Agreement, legal obligations, security,
accounting, dispute resolution and defence of legal claims.

7.5 Where Telemetry Data contains Personal Data, Processor will process it in
accordance with this DPA to the extent Processor acts as Processor, and as an
independent controller to the extent the processing concerns Processor's own
legal, tax, accounting, security, fraud prevention, commercial administration or
legal defence purposes.

7.6 Additional information on Processor's independent-controller processing, if
any, may be provided in a Privacy Policy published by Processor. If no separate
Privacy Policy is available, this Section 7 describes the main categories of
Telemetry Data transmitted to Processor in connection with Orakul.

8. CONFIDENTIALITY

8.1 Processor will ensure that persons authorised to process Personal Data have
committed themselves to confidentiality or are under an appropriate statutory
obligation of confidentiality.

8.2 Processor will restrict access to Personal Data to personnel, contractors
and authorised representatives who need such access for the purposes of
performing the Agreement or this DPA.

8.3 Processor will not disclose Personal Data to any third party except as
permitted by this DPA, the Agreement, Customer's documented instructions or
applicable law.

9. SECURITY MEASURES

9.1 Processor will implement appropriate technical and organisational measures
designed to protect Personal Data against accidental or unlawful destruction,
loss, alteration, unauthorised disclosure or access, taking into account the
state of the art, costs of implementation, nature, scope, context and purposes
of processing, and the risk to Data Subjects.

9.2 Such measures may include, as applicable:

(a) access control and authentication;
(b) least-privilege access for support and administrative personnel;
(c) encryption in transit where supported by the relevant protocol or service;
(d) secure handling of credentials, tokens and API keys provided for support;
(e) logging and monitoring of security-relevant events;
(f) backup and restoration procedures for systems controlled by Processor;
(g) vulnerability management and security updates;
(h) confidentiality obligations for personnel;
(i) segregation of Customer data where technically applicable;
(j) incident response procedures; and
(k) secure deletion or return procedures where applicable.

9.3 Customer is responsible for security measures within Customer's own
environment, including server hardening, operating system updates, database
security, access permissions, user management, network security, secrets
management, backup configuration, integration permissions, AI Provider settings
and protection of API keys, tokens and credentials.

9.4 A description of technical and organisational measures is set out in Annex
2.

10. SUBPROCESSORS ENGAGED BY PROCESSOR

10.1 Customer grants Processor a general authorisation to engage Subprocessors
for processing Personal Data on behalf of Customer in connection with the
Services, subject to this Section 10.

10.2 Processor will maintain a list of Subprocessors engaged by Processor at:

https://orakul.digital/subprocessors

or at another URL notified by Processor in the Agreement, on the website, by
email or through the Orakul interface.

10.3 The Subprocessor list will identify, where reasonably practicable:

(a) the name of the Subprocessor;
(b) the processing activity;
(c) the country or region of processing;
(d) the type of service provided; and
(e) where applicable, relevant transfer safeguards.

10.4 Processor may add or replace Subprocessors by updating the Subprocessor
list and, where required by Applicable Data Protection Laws, providing notice by
email, website notice, product notice or other reasonable means.

10.5 Customer may object to a new Subprocessor on reasonable data protection
grounds by notifying Processor in writing within ten (10) days after notice of
the new Subprocessor or publication of the updated Subprocessor list.

10.6 If Customer objects, the Parties will discuss in good faith a commercially
reasonable solution. If no solution is available, Processor may either refrain
from using the relevant Subprocessor for Customer or permit Customer to
terminate the affected Services in accordance with the Agreement.

10.7 Processor will impose data protection obligations on Subprocessors that
are materially equivalent to those imposed on Processor under this DPA, to the
extent applicable to the nature of the services provided by the Subprocessor.

10.8 Processor remains responsible to Customer for the performance of
Processor's obligations by Subprocessors engaged by Processor.

10.9 For clarity, AI Providers and Customer-Configured Integrations selected,
configured or used by Customer with Customer's own accounts, API keys, tokens,
credentials or subscriptions are not Subprocessors engaged by Processor and are
not included in Processor's Subprocessor list.

11. INTERNATIONAL TRANSFERS

11.1 Customer acknowledges that Processor is established in Georgia. Where
Customer is established in the European Economic Area, the United Kingdom or
another jurisdiction that restricts international transfers of Personal Data,
the transfer of Personal Data from Customer to Processor may constitute an
international transfer.

11.2 The Parties acknowledge that, as of the effective date of this DPA, Georgia
may not be subject to an adequacy decision of the European Commission for the
purposes of Article 45 GDPR. Customer should verify the current status with its
legal counsel before transferring Personal Data to Processor.

11.3 Where the GDPR applies and the transfer of Personal Data from Customer as
controller in the EEA to Processor in Georgia requires an appropriate safeguard
under Article 46 GDPR, the Parties agree that the Standard Contractual Clauses
adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021
("EU SCCs") are incorporated into and form part of this DPA as follows:

(a) Module Two: Controller to Processor applies;
(b) Clause 7, Docking Clause, applies;
(c) Clause 9, Option 2, General Written Authorisation, applies, with the time
period for prior notice of Subprocessor changes set out in Section 10 of
this DPA;
(d) Clause 11(a), Redress, applies and the optional wording does not apply;
(e) Clause 17, Governing Law, shall be the law of an EU Member State that
allows for third-party beneficiary rights. Unless the Parties agree
otherwise in writing, this shall be the law of Ireland;
(f) Clause 18(b), Choice of Forum and Jurisdiction, shall be the courts of
Ireland;
(g) Annex I to the EU SCCs is completed by Annex 1 to this DPA;
(h) Annex II to the EU SCCs is completed by Annex 2 to this DPA; and
(i) Annex III to the EU SCCs is completed by the Subprocessor list described in
Section 10 of this DPA, where applicable.

11.4 Where the UK GDPR applies and the transfer of Personal Data from Customer
in the United Kingdom to Processor in Georgia requires an appropriate safeguard,
the Parties agree that the UK International Data Transfer Addendum to the EU
Commission Standard Contractual Clauses, issued by the UK Information
Commissioner's Office and laid before Parliament in accordance with section
119A of the Data Protection Act 2018 ("UK Addendum"), is incorporated into and
forms part of this DPA. The EU SCCs, as modified by the UK Addendum, apply to
such transfer.

11.5 Where the Swiss Federal Act on Data Protection applies, the EU SCCs apply
with necessary amendments to reflect Swiss law and the competent Swiss
supervisory authority, to the extent required.

11.6 Where Processor engages a Subprocessor in a third country and Applicable
Data Protection Laws require transfer safeguards, Processor will ensure that an
appropriate transfer mechanism is in place for transfers by Processor to such
Subprocessor.

11.7 Sections 11.3 to 11.6 apply only to transfers involving Processor or
Subprocessors engaged by Processor. They do not apply to AI Providers or
Customer-Configured Integrations selected, configured or used by Customer under
Sections 4 and 5. Customer is responsible for transfer mechanisms for such
providers and integrations.

12. ASSISTANCE TO CUSTOMER

12.1 Taking into account the nature of processing and the information available
to Processor, Processor will provide reasonable assistance to Customer, at
Customer's expense unless otherwise required by Applicable Data Protection Laws,
in relation to:

(a) responding to Data Subject requests;
(b) security of processing;
(c) Personal Data Breach notifications;
(d) data protection impact assessments;
(e) prior consultation with Supervisory Authorities; and
(f) demonstrating compliance with obligations under Applicable Data Protection
Laws.

12.2 Processor's assistance is limited to processing activities for which
Processor acts as Processor. Processor is not responsible for assisting with
Customer's independent use of AI Providers, Customer-Configured Integrations,
Customer's own infrastructure, Customer's employee accounts, Customer's backup
destinations or Customer's third-party providers, except to the extent Processor
has information reasonably available and agrees to provide assistance.

12.3 If Customer requests assistance requiring significant time, technical work,
custom development, legal analysis, forensic work or third-party costs,
Processor may charge reasonable fees or require a separate statement of work.

13. DATA SUBJECT REQUESTS

13.1 If Processor receives a request from a Data Subject relating to Personal
Data processed on behalf of Customer, Processor will, where legally permitted,
promptly notify Customer or direct the Data Subject to Customer.

13.2 Processor will not respond to the substance of such request unless
instructed by Customer or required by applicable law.

13.3 Customer is responsible for responding to Data Subject requests, including
requests relating to data processed by AI Providers and Customer-Configured
Integrations selected or configured by Customer.

14. PERSONAL DATA BREACH

14.1 Processor will notify Customer without undue delay after becoming aware of
a Personal Data Breach affecting Personal Data processed by Processor on behalf
of Customer.

14.2 The notification will include information reasonably available to Processor,
which may include:

(a) the nature of the Personal Data Breach;
(b) categories and approximate number of Data Subjects concerned;
(c) categories and approximate number of records concerned;
(d) likely consequences of the breach;
(e) measures taken or proposed to address the breach; and
(f) contact point for further information.

14.3 Processor's notification of a Personal Data Breach is not an admission of
fault or liability.

14.4 Customer is responsible for assessing whether notification to Supervisory
Authorities or Data Subjects is required.

14.5 Processor is not responsible for breach notification obligations arising
from Customer's own environment, AI Providers, Customer-Configured Integrations,
Customer's backups, Customer's API keys, Customer's credentials, Customer's
employees or Customer's third-party providers, except to the extent Processor is
legally responsible for the relevant breach.

15. RETURN AND DELETION

15.1 Upon termination of the Services or upon Customer's written request,
Processor will delete or return Personal Data processed on behalf of Customer,
unless applicable law requires retention.

15.2 This obligation applies only to Personal Data held by Processor. It does
not apply to data stored in Customer's own environment, Customer's backups,
AI Providers, Customer-Configured Integrations, Customer's cloud storage,
Customer's logs or Customer's third-party services.

15.3 Processor may retain copies of Personal Data to the extent required by
applicable law, tax, accounting, audit, security, backup, dispute resolution or
legal defence obligations, subject to appropriate confidentiality and security
measures.

15.4 Deletion from backups may occur according to Processor's ordinary backup
rotation and retention schedules.

16. AUDITS AND INFORMATION

16.1 Processor will make available to Customer information reasonably necessary
to demonstrate compliance with this DPA, subject to confidentiality, security,
commercial sensitivity and protection of other customers' data.

16.2 Customer may request an audit not more than once per calendar year, unless
required more frequently by Applicable Data Protection Laws or following a
confirmed Personal Data Breach caused by Processor.

16.3 Audits must be conducted during normal business hours, with reasonable
advance written notice, in a manner that does not disrupt Processor's business,
systems, security or services.

16.4 Processor may satisfy audit requests by providing security summaries,
policies, questionnaires, certifications, third-party reports or written
responses, where appropriate.

16.5 Customer will bear its own audit costs and reimburse Processor for
reasonable time and expenses incurred in supporting an audit, unless prohibited
by Applicable Data Protection Laws.

16.6 Audits do not extend to AI Providers or Customer-Configured Integrations
selected, configured or used by Customer, or to Processor's other customers,
internal financial records, trade secrets or unrelated systems.

17. ACCEPTANCE OF THIS DPA

17.1 This DPA may be accepted by signature, by reference in an order or
Agreement, by electronic acceptance, by clicking an acceptance checkbox in the
installer or administrative interface, or by installing, activating or using
Orakul after this DPA has been made available to Customer.

17.2 Where Orakul records electronic acceptance of this DPA, Processor may store
evidence of acceptance, including the accepted DPA hash, date and time of
acceptance, IP address of the accepting person or system, licence key,
installation domain, software version, build identifier and related technical
metadata.

17.3 Customer agrees that electronic acceptance of this DPA is valid and binding
to the fullest extent permitted by applicable law. If the person accepting this
DPA acts on behalf of an organisation, that person represents that they are
authorised to bind that organisation.

17.4 If the Agreement or EULA states that a separate DPA will be concluded, this
DPA constitutes that separate data processing agreement once accepted under this
Section 17 or incorporated by reference into the Agreement.

18. LIABILITY

18.1 Each Party's liability under this DPA is subject to the limitations and
exclusions of liability set out in the Agreement, unless and to the extent such
limitations are prohibited by Applicable Data Protection Laws.

18.2 Nothing in this DPA limits liability that cannot be limited under
Applicable Data Protection Laws, including liability to Data Subjects where such
liability cannot lawfully be excluded or restricted.

18.3 Where the Agreement contains a liability cap based on amounts paid during a
specified period and Customer purchased a perpetual or one-time licence, the
cap shall be interpreted, to the extent legally permissible, by reference to the
amounts actually paid for the affected licence and any paid support,
maintenance, update or service fees during the relevant period. If such
interpretation is not enforceable under Applicable Data Protection Laws, the
mandatory rules of Applicable Data Protection Laws shall prevail.

18.4 Processor is not liable for processing, transfers, breaches, claims,
losses, regulatory actions or damages arising from AI Providers or
Customer-Configured Integrations selected, configured or used by Customer,
except to the extent caused by Processor's breach of this DPA or applicable law.

19. GOVERNING LAW AND ORDER OF PRECEDENCE

19.1 This DPA is governed by the governing law specified in the Agreement,
except to the extent otherwise required by Applicable Data Protection Laws or
the EU SCCs, UK Addendum or other mandatory transfer mechanism.

19.2 In the event of conflict between this DPA and the Agreement, this DPA will
prevail with respect to the processing of Personal Data on behalf of Customer.

19.3 In the event of conflict between this DPA and the EU SCCs or UK Addendum,
the EU SCCs or UK Addendum will prevail to the extent of the conflict.

19.4 This DPA does not reduce any mandatory rights of Data Subjects under
Applicable Data Protection Laws.

20. NOTICES

20.1 Notices to Processor regarding this DPA must be sent to:

Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia
Taxpayer / Registration No.: 304589032
Legal address: 19/3 Rustavi Highway, Tbilisi, Georgia
E-mail: max@orakul.digital

20.2 Notices to Customer may be sent to the email address, account contact,
billing contact, administrative contact or other contact details provided by
Customer.

20.3 Notices may be sent electronically unless Applicable Data Protection Laws
or the Agreement require another form.

ANNEX 1

DETAILS OF PROCESSING

A. LIST OF PARTIES

Data Exporter / Controller:

The customer, licensee or user that purchases, installs, accesses or uses
Orakul, or on whose behalf Orakul is used.

Role: Controller.

Contact details: As provided in the applicable order, account, invoice,
purchase confirmation, support request or other commercial documentation.

Data Importer / Processor:

Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia
Taxpayer / Registration No.: 304589032
Legal address: 19/3 Rustavi Highway, Tbilisi, Georgia
E-mail: max@orakul.digital

Role: Processor, except where acting as an independent controller for limited
business administration, accounting, legal, security, fraud prevention or legal
defence purposes.

B. SUBJECT MATTER OF PROCESSING

Processing of Personal Data in connection with licensing, activation,
maintenance, support, diagnostics, implementation, updates and use of Orakul.

C. DURATION OF PROCESSING

For the term of the Agreement and thereafter for the period necessary to comply
with legal, tax, accounting, audit, security, backup, dispute resolution and
legal defence obligations, unless earlier deletion is required by Applicable
Data Protection Laws.

D. NATURE AND PURPOSE OF PROCESSING

The nature of processing may include collection, receipt, access, recording,
organisation, structuring, storage, adaptation, alteration, retrieval,
consultation, use, disclosure by transmission, alignment, combination,
restriction, deletion, destruction and other operations necessary to provide the
Services.

The purposes of processing are:

(a) licence activation and verification;
(b) maintenance, updates and technical support;
(c) installation, implementation and configuration assistance;
(d) diagnostics, troubleshooting and security;
(e) processing support tickets and communications;
(f) verifying acceptance of legal terms;
(g) fraud prevention and licence abuse prevention;
(h) compliance with legal obligations; and
(i) performance of the Agreement and documented Customer instructions.

E. CATEGORIES OF DATA SUBJECTS

Depending on Customer's use of Orakul, Data Subjects may include:

(a) Customer's employees, contractors, agents and representatives;
(b) Customer's clients, leads, prospects and business contacts;
(c) users of Customer's websites, systems or services;
(d) persons appearing in Customer's emails, documents, CRM records,
correspondence, knowledge base, prompts, webpages, analytics records,
calendar entries, drive files or other Customer Data;
(e) support contacts and administrative users;
(f) persons whose IP addresses or technical identifiers are processed in
connection with activation, logging or security.

F. CATEGORIES OF PERSONAL DATA

Depending on Customer's use of Orakul, Personal Data may include:

(a) names, job titles, roles and employer details;
(b) email addresses, phone numbers and contact details;
(c) user IDs, account IDs and technical identifiers;
(d) IP addresses, domains, device and server metadata;
(e) correspondence, email content, messages and chat records;
(f) calendar entries and meeting information;
(g) CRM records, lead records and customer records;
(h) knowledge base documents, files, webpages, prompts and generated outputs;
(i) analytics, webmaster and website performance data;
(j) licence key, installation domain, tariff branch, build identifier, software
version, panel language, accepted EULA hash, accepted DPA hash, acceptance
time and acceptance IP address;
(k) logs, diagnostic data and support materials submitted by Customer;
(l) backup files, database dumps and exports if submitted to or processed by
Processor.

G. SPECIAL CATEGORIES OF PERSONAL DATA

Orakul is not specifically designed to process Special Categories of Personal
Data. Customer must not submit Special Categories of Personal Data to Processor
unless Customer has a valid legal basis, has implemented appropriate safeguards
and has instructed Processor accordingly.

Special Categories of Personal Data may be processed incidentally if Customer
includes them in prompts, messages, documents, CRM records, emails, calendar
entries, drive files, support materials or other Customer Data.

H. FREQUENCY OF TRANSFER

Continuous or occasional, depending on Customer's use of Orakul, licence
verification, support requests, implementation work, telemetry, diagnostics and
Customer's configuration.

I. PLACE OF PROCESSING BY PROCESSOR

Processor is established in Georgia. Personal Data processed by Processor may be
processed in Georgia and in locations where Processor's authorised personnel,
contractors or Processor-engaged Subprocessors listed under Section 10 are
located, subject to the transfer safeguards described in Section 11.

For SCC purposes, the primary importer location is Georgia. Additional
Subprocessor locations, if any, are identified in the Subprocessor list
described in Section 10.

J. CUSTOMER-CONTROLLED THIRD-PARTY FLOWS

The following processing flows may occur under Customer's own configuration and
responsibility and are not transfers to Processor or Processor-engaged
Subprocessors unless Processor separately engages the relevant provider:

(a) transfer of prompts, messages, correspondence, knowledge base documents,
webpage text, files and other Customer Data to AI Providers selected or
configured by Customer, including OpenAI, Google Gemini, Anthropic Claude
or OpenRouter;
(b) access to or transmission of data through Google Workspace, including
Gmail, Google Calendar and Google Drive;
(c) access to or transmission of data through Bitrix24;
(d) access to or transmission of analytics data through Yandex Metrica;
(e) access to or transmission of webmaster/search data through Yandex
Webmaster;
(f) export, backup or database dump transmission to Yandex Disk or other cloud
storage configured by Customer;
(g) any other external service, API, webhook, database, storage, CRM, analytics,
email, calendar or workspace account connected by Customer.

Customer is responsible for the legal basis, notices, contracts, transfer
mechanisms, transfer risk assessments, security settings and compliance of such
flows.

ANNEX 2

TECHNICAL AND ORGANISATIONAL MEASURES

Taking into account the nature of the Services and the fact that Orakul may be
operated in Customer's own environment, technical and organisational measures
are allocated between Processor and Customer as follows.

1. Measures controlled by Processor

Processor will implement appropriate measures for systems and processing
activities under Processor's control, which may include:

(a) access control for Processor personnel and support systems;
(b) limiting access to Personal Data to persons with a need to know;
(c) confidentiality obligations for authorised personnel;
(d) secure communication channels where reasonably available;
(e) logging of licence activation, DPA/EULA acceptance and security-relevant
server events;
(f) protection of licensing and activation systems;
(g) secure handling of support materials submitted by Customer;
(h) deletion or return of support materials when no longer needed, subject to
legal retention requirements;
(i) vulnerability management for Processor-controlled systems;
(j) incident response procedures;
(k) backup and recovery procedures for Processor-controlled systems where
applicable;
(l) review of Subprocessors engaged by Processor;
(m) contractual data protection obligations for Processor-engaged
Subprocessors.

2. Measures controlled by Customer

Customer is responsible for implementing and maintaining appropriate security
measures in Customer's own environment, including:

(a) server, operating system and database security;
(b) network security, firewall and access restrictions;
(c) secure management of administrator accounts and user permissions;
(d) authentication and password policies;
(e) secure storage of API keys, OAuth tokens, credentials and secrets;
(f) appropriate configuration of AI Providers;
(g) appropriate configuration of Google Workspace, Bitrix24, Yandex Metrica,
Yandex Webmaster, Yandex Disk and other integrations;
(h) limiting access to employee mailboxes, calendars, drive files, CRM records,
analytics accounts and webmaster accounts;
(i) backup destination selection, encryption and retention;
(j) database dump protection;
(k) monitoring of Customer's own infrastructure;
(l) patching and updating Customer's servers and dependencies;
(m) assessment of third-party providers selected by Customer;
(n) legal basis, notices and transfer mechanisms for Customer-controlled
processing flows.

3. Encryption

Processor will use encryption in transit where supported and appropriate for
Processor-controlled systems. Customer is responsible for enabling and
maintaining encryption for Customer's own servers, databases, backups,
integrations and external services.

4. Availability and resilience

Processor will maintain reasonable availability and resilience measures for
Processor-controlled licensing, support and administrative systems. Customer is
responsible for availability, backup, disaster recovery and resilience of
Customer's own Orakul installation, database, connected services and backup
destinations.

5. Segregation

Where Processor processes data of multiple customers in Processor-controlled
systems, Processor will use logical or organisational segregation measures
appropriate to the nature of the system. Customer is responsible for segregation
of users, roles, workspaces, environments and databases in Customer's own
deployment.

6. Audit and review

Processor may periodically review and update its technical and organisational
measures. Customer should periodically review its own configuration, connected
providers, permissions, transfer mechanisms and security controls.

ANNEX 3

SUBPROCESSORS ENGAGED BY PROCESSOR

Processor will maintain the current list of Subprocessors engaged by Processor
at:

https://orakul.digital/subprocessors

The list may include providers used for hosting, email delivery, customer
support, analytics, licensing, payment processing, accounting, communications,
security, development operations or other services required to provide the
Services.

For clarity, the following are not Processor-engaged Subprocessors merely
because Customer configures them in Orakul with Customer's own account, token,
API key, credentials or subscription:

(a) OpenAI;
(b) Google Gemini;
(c) Anthropic Claude;
(d) OpenRouter;
(e) Google Workspace;
(f) Bitrix24;
(g) Yandex Metrica;
(h) Yandex Webmaster;
(i) Yandex Disk;
(j) any other AI provider, CRM, analytics service, webmaster tool, email
provider, calendar provider, drive, storage, API, webhook or integration
selected or configured by Customer.

Customer remains responsible for these Customer-selected providers as described
in Sections 4 and 5 of this DPA.

ANNEX 4

COMMERCIAL AND PAYMENT DETAILS

Processor / Service Provider:

Maksim Safianov, Individual Entrepreneur (P/E) registered in Georgia
Taxpayer / Registration No.: 304589032
Legal address: 19/3 Rustavi Highway, Tbilisi, Georgia
E-mail for notices: max@orakul.digital

Bank details:

Bank: JSC TBC Bank, Tbilisi, Georgia
SWIFT/BIC: TBCBGE22
IBAN: GE51TB7247645064400002
Beneficiary name: MAKSIM SAFIANOV
Intermediary bank for USD/EUR: Citibank N.A., New York, USA
Intermediary bank SWIFT: CITIUS33