ARGYLL DATA DEVELOPMENT

Website Data Processing Addendum

Final Review Copy - Not for Publication

Version 1.0

Effective date 26 July 2026

Company Argyll Data Development Ltd

Company number SC759203

Public website document

Status adopted and issued

Public terms apply automatically when Argyll processes personal data on a customer’s behalf.

Important: This is the public website version of the Addendum. It is intended to be incorporated electronically into Argyll Data Development’s online customer terms and does not require a wet signature. The sub-processor register, international-transfer arrangements and operational details must be confirmed before publication.

Website Data Processing Addendum

This Website Data Processing Addendum (the “Addendum”) applies between Argyll Data Development Ltd, a company incorporated in Scotland with company number SC759203 (“Argyll”, “ADD”, “we”, “us” or “our”), and each customer that accepts or is otherwise bound by the Platform, Software and AI Services Terms or another online agreement governing use of the Services (“Customer”).

This Addendum supplements and forms part of the Platform, Software and AI Services Terms and any online Order Form or other electronic agreement under which Argyll provides the Services to the Customer (the “Agreement”). It applies automatically where Argyll processes Customer Personal Data on the Customer’s behalf. A separate signature is not required.

Where Argyll processes Customer Personal Data on behalf of the Customer, this Addendum sets out the parties’ obligations under Data Protection Law. If there is a conflict between this Addendum and the Agreement concerning the processing of Customer Personal Data, this Addendum prevails to the extent of that conflict. If Argyll and the Customer enter into a separately signed enterprise data processing agreement, that signed agreement prevails over this Addendum to the extent of any conflict.

Electronic acceptance. The Customer accepts this Addendum by creating or using an account, placing an online order, accepting the Agreement electronically, or continuing to use the Services after this Addendum is made available or updated in accordance with the Agreement.

1. Definitions and interpretation

Defined term

Meaning

“Applicable Law”

all laws and regulatory requirements applicable to a party in connection with the Agreement.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority”

have the meanings given in Data Protection Law.

“Customer Personal Data”

Personal Data Processed by or on behalf of Argyll as Processor in connection with providing the Services to the Customer.

“Data Protection Law”

the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any legislation replacing, amending or supplementing them, in each case as applicable to the Processing.

“Restricted Transfer”

a transfer of Personal Data for which an adequacy regulation is not available and which requires an appropriate safeguard under Data Protection Law.

“Services”

the platform, software, artificial intelligence, model-access, API, managed-service, support and related services supplied under the Agreement.

“Sub-processor”

a third party appointed by or on behalf of Argyll to Process Customer Personal Data.

“UK GDPR”

the retained EU law version of the General Data Protection Regulation as it forms part of the law of the United Kingdom, as amended from time to time.

References to a statutory provision include that provision as amended, extended, re-enacted or replaced. Headings are for convenience only. The words “including” and “includes” are illustrative and do not limit the words preceding them.

2. Scope and roles of the parties

The Customer is the Controller and Argyll is the Processor in relation to Customer Personal Data, except where the parties expressly agree otherwise in writing or where Argyll independently determines the purposes and means of Processing.

Each party is responsible for complying with the obligations that apply to it under Data Protection Law.

The Customer warrants that its instructions to Argyll, its use of the Services and its provision of Customer Personal Data are lawful, fair and transparent, and that it has provided all required notices and obtained any required consents or other lawful basis.

Where the Customer acts as a Processor for another Controller, the Customer appoints Argyll as a sub-processor and confirms that it has authority to give the instructions contained in the Agreement and this Addendum.

Argyll may Process limited Personal Data as an independent Controller for legitimate business purposes such as account administration, security, fraud prevention, billing, legal compliance, service communications and relationship management. Such Processing is governed by Argyll’s Privacy Notice and not by this Addendum.

3. Processing instructions

Argyll shall Process Customer Personal Data only on the Customer’s documented instructions, including the instructions set out in the Agreement, this Addendum, an applicable Order Form and the Customer’s authorised use and configuration of the Services.

Argyll may Process Customer Personal Data where required by Applicable Law. Unless prohibited by law, Argyll shall inform the Customer of that legal requirement before Processing.

Argyll shall promptly inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Law. Argyll may suspend the affected Processing until the parties agree a lawful instruction.

The Customer shall not instruct Argyll to Process Personal Data in a manner that is unlawful or outside the agreed scope of the Services.

4. Details of the Processing

The subject matter, duration, nature and purpose of the Processing, the categories of Personal Data and the categories of Data Subjects are described in Schedule 1. The Customer may provide additional documented instructions through an Order Form or written service specification, provided they are consistent with the Agreement and Data Protection Law.

5. Confidentiality and personnel

Argyll shall ensure that persons authorised to Process Customer Personal Data are subject to an appropriate duty of confidentiality.

Argyll shall limit access to Customer Personal Data to personnel and contractors who require access to perform the Services or meet legal obligations.

Argyll shall provide appropriate data-protection and information-security training to relevant personnel.

6. Security of Processing

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing, and the risk to the rights and freedoms of individuals, Argyll shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

The baseline measures are described in Schedule 2. Argyll may update those measures where the update does not materially reduce the overall security of the Services.

The Customer is responsible for securely configuring and using the Services, protecting account credentials and API keys, applying appropriate access controls, and assessing whether the Services are suitable for the categories and sensitivity of Personal Data it submits.

The Customer shall not submit special category data, criminal-offence data, children’s data, biometric data used for identification, or other highly sensitive Personal Data unless expressly permitted in the applicable Order Form and supported by agreed safeguards.

7. Sub-processors

The Customer gives Argyll general written authorisation to appoint Sub-processors to support delivery of the Services, subject to this clause.

Before this Addendum is published or used for general online sales, Argyll shall confirm and document each current Sub-processor, the location and nature of its Processing, and any applicable international-transfer safeguard. Once confirmed, Argyll shall make that information available to Customers through an appropriate notice, register or service document.

Argyll shall give the Customer reasonable advance notice of a new or replacement Sub-processor. The Customer may object on reasonable data-protection grounds by notifying Argyll within the period stated in that notice.

The parties shall work in good faith to address a valid objection. If no commercially reasonable alternative is available, Argyll may suspend or terminate the affected Service on written notice, and the Customer’s sole remedy shall be a pro-rata refund of prepaid fees for the terminated period, where applicable.

Argyll shall enter into a written agreement with each Sub-processor imposing data-protection obligations that provide a level of protection materially equivalent to the relevant obligations in this Addendum.

Argyll remains responsible to the Customer for the performance of its Sub-processors’ obligations to the extent required by Data Protection Law.

8. International transfers

Argyll shall not make a Restricted Transfer unless it has implemented a lawful transfer mechanism and completed any assessment required by Data Protection Law.

Where applicable, Argyll may rely on an adequacy regulation, the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses, binding corporate rules, or another lawful safeguard.

Where the UK International Data Transfer Agreement or UK Addendum is required, the parties shall execute or incorporate the applicable approved terms and complete the required tables and transfer details. Those approved terms shall prevail over this Addendum to the extent of any conflict concerning the Restricted Transfer.

Argyll shall implement any supplementary technical, contractual or organisational measures reasonably identified through the applicable transfer risk assessment or data protection test.

The Customer acknowledges that remote access to Customer Personal Data from outside the United Kingdom may constitute a Restricted Transfer and shall provide information reasonably required to assess and document the transfer.

9. Data Subject rights

Taking into account the nature of the Processing, Argyll shall provide reasonable assistance through appropriate technical and organisational measures to enable the Customer to respond to requests by Data Subjects exercising their rights under Data Protection Law.

If Argyll receives a request directly from a Data Subject concerning Customer Personal Data, Argyll shall promptly forward it to the Customer and shall not respond except on the Customer’s documented instructions or where required by Applicable Law.

The Customer is responsible for verifying the identity and entitlement of the requester and for determining the appropriate response.

10. Assistance with compliance

Taking into account the nature of the Processing and information available to Argyll, Argyll shall provide reasonable assistance with the Customer’s obligations concerning security, Personal Data Breaches, data protection impact assessments and prior consultation with a Supervisory Authority.

Where assistance requires material work beyond the ordinary operation of the Services, Argyll may charge reasonable fees based on the time and resources required, unless the assistance is required because of Argyll’s breach of this Addendum.

11. Personal Data Breaches

Notification by Argyll

Argyll shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by Argyll under this Addendum.

The notification shall, to the extent that information is available at the time, describe: (a) the nature of the Personal Data Breach; (b) the categories and approximate number of affected Data Subjects; (c) the categories and approximate number of affected personal data records; (d) the likely consequences; (e) the measures taken or proposed to address, contain and mitigate the breach; and (f) a contact point from whom further information may be obtained.

Argyll may provide information in phases where it is not possible to provide all relevant information at the same time.

Notification by the Customer

The Customer shall notify Argyll without undue delay after becoming aware of any actual or suspected Personal Data Breach, security incident or unauthorised access that: (a) affects or may affect Customer Personal Data processed through the Services; (b) arises from the Customer’s systems, personnel, users, devices, access credentials or instructions; (c) may compromise the security, confidentiality, integrity or availability of the Services; or (d) may require investigation, containment, remediation or regulatory reporting by Argyll.

The Customer’s notification shall include all information reasonably available concerning the incident, including its nature, scope, timing, likely consequences and any steps already taken.

Immediate protective action

Where either party becomes aware of an actual or suspected Personal Data Breach, both parties shall take reasonable and proportionate steps to contain the incident, prevent further unauthorised access or loss, preserve relevant evidence, investigate the cause and effects, mitigate adverse consequences, and support any legally required notification or remedial action.

Where urgent action is reasonably necessary to protect Customer Personal Data, the Services or affected Data Subjects, Argyll may temporarily suspend affected accounts, credentials, integrations or Processing activities. Argyll shall inform the Customer as soon as reasonably practicable of any such action.

Cooperation and information sharing

Each party shall provide the other with reasonable cooperation and information necessary to investigate, manage and respond to a Personal Data Breach. Neither party shall knowingly provide inaccurate, incomplete or misleading information concerning the incident.

The parties shall coordinate external communications where reasonably practicable, except where Applicable Data Protection Law requires either party to act independently or within a specified period.

Regulatory and Data Subject notifications

The Customer, acting as Controller, is responsible for determining whether notification must be made to a Supervisory Authority or affected Data Subjects and for making such notification where required. Argyll shall provide reasonable assistance, taking into account the nature of the Processing and the information available to Argyll.

Where Applicable Data Protection Law places a notification obligation directly upon Argyll, Argyll may make the required notification and shall inform the Customer unless prohibited by law.

No admission of liability

A notification, investigation, remedial action or other response by either party concerning an actual or suspected Personal Data Breach shall not, by itself, constitute an admission of fault, negligence or liability.

12. Records, information and audits

Argyll shall make available information reasonably necessary to demonstrate compliance with the Processor obligations in Data Protection Law and this Addendum.

Argyll may satisfy audit requests by providing current independent assurance reports, certifications, security documentation, questionnaires, summaries of penetration testing or other appropriate evidence, subject to confidentiality and security restrictions.

Where the information provided is not reasonably sufficient, the Customer may conduct one audit in any twelve-month period, or more frequently where required by a Supervisory Authority or following a material Personal Data Breach attributable to Argyll.

Audits must be conducted on reasonable written notice, during normal business hours, without disrupting operations, and by personnel or an independent auditor bound by confidentiality. The audit shall not require access to information relating to other customers, trade secrets, privileged material, vulnerability details that would create security risk, or areas outside the scope of the Processing.

The Customer shall bear its audit costs and reimburse Argyll’s reasonable costs, unless the audit identifies a material breach by Argyll.

13. Return and deletion

On termination or expiry of the relevant Services, and at the Customer’s choice, Argyll shall delete or return Customer Personal Data within a reasonable period, except to the extent retention is required by Applicable Law or the data remains in secure backup systems pending deletion through the ordinary backup cycle.

Where Customer Personal Data is retained under Applicable Law or in backups, Argyll shall continue to protect it under this Addendum and shall not actively Process it except for legal compliance, security, recovery testing or restoration.

The Customer is responsible for exporting Customer Personal Data before termination where the Services provide export functionality.

14. Liability

The liability of each party arising from or in connection with this Addendum is subject to the exclusions and limitations of liability in the Agreement, except to the extent those exclusions or limitations are prohibited by Data Protection Law. Nothing in this Addendum limits the rights of Data Subjects or the powers of a Supervisory Authority.

15. Changes to Data Protection Law

The parties shall cooperate in good faith to amend this Addendum where reasonably necessary to comply with a change in Data Protection Law, binding regulatory guidance or an approved transfer mechanism.

Argyll may update this Addendum by publishing a revised version where the change is required by law, improves protection, reflects changes to the Services, or is otherwise reasonable and does not materially reduce the Customer’s rights. Material changes shall be notified in accordance with the Agreement.

16. Order of precedence and survival

The order of precedence is: (a) mandatory provisions of an approved international-transfer mechanism; (b) any separately signed enterprise data processing agreement; (c) this Addendum; (d) the applicable online Order Form; and (e) the remainder of the Agreement, unless a document expressly states a different order that is permitted by Data Protection Law.

Clauses intended by their nature to survive termination, including confidentiality, international transfers, audits, return and deletion, and liability, shall survive termination of the Agreement.

17. Governing law and jurisdiction

This Addendum is governed by the governing law and jurisdiction specified in the Agreement. If the Agreement does not specify them, this Addendum is governed by Scots law and the courts of Scotland shall have exclusive jurisdiction, without prejudice to the rights of Data Subjects and Supervisory Authorities under Data Protection Law.

Schedule 1 - Details of Processing

Subject matter

Provision, administration, operation, support, monitoring and security of the Services used by the Customer.

Duration

For the term of the Agreement and any limited period thereafter required for return, deletion, backup rotation, dispute handling or legal compliance.

Nature of Processing

Collection, receipt, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, generation, analysis, hosting, support, monitoring, restriction, deletion and destruction, as necessary to provide the Services.

Purposes

To provide and secure the Services; authenticate users; manage accounts; support customer onboarding undertaken by Argyll and SambaNova; process prompts, inputs and outputs; provide APIs and model access; deliver technical support; process billing through Stripe; undertake service communications and analytics through Argyll and SambaNova; monitor performance and abuse; maintain service integrity; and comply with documented Customer instructions.

Primary hosting location

Customer service infrastructure is currently hosted at the Equinix Manchester data-centre facility in Manchester, United Kingdom. This is the only production hosting location currently used by Argyll. Remote access or ancillary Processing by authorised Sub-processors may occur from other locations identified in Schedule 3 and remains subject to clause 8.

Data Subjects

Customer personnel, authorised users, contractors, representatives, end users, prospective users, business contacts and other individuals whose Personal Data the Customer submits to the Services.

Categories of Personal Data

Contact and identity data; professional and employment information; account and authentication data; device, network and usage data; support communications; billing and transaction metadata; prompts, inputs, files, content and outputs containing Personal Data; and other Personal Data submitted by the Customer within the permitted scope of the Services.

Special categories

Not intended unless expressly authorised in an Order Form and supported by agreed safeguards. The Customer must not submit prohibited sensitive data contrary to clause 6.4.

Frequency

Continuous, intermittent or event-driven, depending on the Customer’s use of the Services.

Retention

For the period configured or agreed for the Service, followed by deletion or return in accordance with clause 13 and applicable backup-retention cycles.

Documented instructions

The Agreement, this Addendum, applicable Order Forms, service configurations, support requests and other written instructions accepted by Argyll.

Argyll Data Development Ltd | Company No. SC759203 | Website Data Processing Addendum Final Review Copy