BACI

INTERNATIONAL DATA TRANSFERS

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

This International Data Transfer Addendum ("Transfer Addendum") forms part of the Agreement between BACI LLC ("BACI") and Customer and governs Restricted Transfers of Personal Data in connection with the Services.

This Transfer Addendum is designed to provide a scalable contractual framework for transfers subject to the European Union General Data Protection Regulation ("EU GDPR"), United Kingdom data-protection law and other Applicable Data Protection Laws that require safeguards for cross-border transfers. It supplements the BACI Data Processing Addendum ("DPA") and does not replace mandatory transfer instruments where those instruments apply.

BACI will not represent that a particular adequacy decision, certification, privacy framework, binding corporate rules programme or other transfer mechanism applies unless the relevant status has actually been obtained, maintained and is legally applicable to the transfer.

1. SCOPE

This Transfer Addendum applies where Personal Data is transferred, made available, remotely accessed or otherwise Processed across borders in circumstances that constitute a Restricted Transfer under Applicable Data Protection Law.

It applies to transfers by Customer to BACI, by BACI to authorised Subprocessors, and to other transfers within the scope of the Agreement where BACI is contractually responsible for implementing a transfer safeguard.

It does not create a transfer restriction where Applicable Data Protection Law does not treat the relevant Processing as a Restricted Transfer.

2. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

This Transfer Addendum forms part of the BACI Legal Framework and should be read with the Terms of Service, Privacy Policy, DPA, Security Policy / Security Addendum, Data Retention & Deletion Policy, Subprocessor Policy & List and applicable Orders and Supplemental Terms.

The DPA governs BACI's Processing of Customer Personal Data on Customer's behalf. This Transfer Addendum governs the transfer mechanism and supplementary transfer protections for Restricted Transfers.

A mandatory transfer instrument controls over inconsistent contractual language to the extent required for that transfer. An executed amendment or Order may establish additional lawful transfer requirements where it expressly addresses them.

3. DEFINITIONS

“Adequacy Decision” means a decision, regulation or equivalent legal determination by a competent authority recognising that a country, territory, sector or international organisation provides the legally required level of protection for relevant transfers.

“Applicable Data Protection Law” has the meaning given in the DPA.

“Data Exporter” means the party making a Restricted Transfer.

“Data Importer” means the party receiving a Restricted Transfer.

“EU SCCs” means the European Commission standard contractual clauses for transfers of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914, as lawfully amended, replaced or superseded.

“Restricted Transfer” means a transfer of Personal Data for which Applicable Data Protection Law requires an adequacy basis, appropriate safeguard, contractual transfer instrument, derogation or equivalent legal mechanism.

“Supplementary Measures” means technical, contractual or organisational protections implemented in addition to a primary transfer mechanism where appropriate.

“Transfer Assessment” means a transfer impact assessment, transfer risk assessment, data protection test or equivalent assessment required by Applicable Data Protection Law.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as lawfully revised or replaced.

Other capitalised terms have the meanings given in the DPA or Agreement.

4. TRANSFER PRINCIPLES

BACI applies the following principles to Restricted Transfers:

(a) use a legally valid transfer basis where required;

(b) identify the actual transfer relationship rather than assuming every international Processing activity requires the same mechanism;

(c) assess relevant destination-country and transfer circumstances where Applicable Law requires;

(d) implement Supplementary Measures where reasonably necessary to satisfy the applicable legal standard;

(e) minimise unnecessary international access to Personal Data;

(f) maintain contractual protections with relevant Subprocessors;

(g) respond appropriately to material changes in law, mechanism validity or transfer risk; and

(h) avoid unsupported claims concerning certifications, adequacy or government-access immunity.

5. ADEQUACY

Where a valid Adequacy Decision lawfully covers a Restricted Transfer, BACI and Customer may rely on that decision without implementing an additional contractual transfer mechanism unless Applicable Law or the Agreement requires otherwise.

If an Adequacy Decision is repealed, suspended, narrowed or ceases to cover the relevant transfer, BACI may implement another lawful transfer mechanism.

Reliance on adequacy applies only within the scope of the relevant legal determination.

6. EU STANDARD CONTRACTUAL CLAUSES

Where the EU GDPR requires an Article 46 transfer safeguard and the EU SCCs are an available lawful mechanism, the EU SCCs are incorporated into the Agreement as specified in Annex I.

The applicable SCC module is determined by the roles of Data Exporter and Data Importer.

BACI and Customer will not amend the EU SCCs in a manner that contradicts them or prejudices Data Subject rights.

Commercial provisions of the Agreement continue to apply to the extent they do not conflict with the mandatory SCCs.

7. SCC MODULE SELECTION

Unless an applicable Order specifies otherwise:

(a) Module One applies where Customer is a Controller and BACI is an independent Controller for the relevant transfer and the EU SCCs lawfully support that relationship;

(b) Module Two applies where Customer is Controller and BACI is Processor;

(c) Module Three applies where Customer is Processor and BACI is Subprocessor; and

(d) Module Four applies where Customer is Processor and BACI is Controller for a transfer falling within that module.

Only the module legally applicable to the relevant transfer is incorporated.

8. EU SCC COMPLETION

The parties' identities are determined from the Agreement and applicable Order.

The transfer description is supplied by the DPA, Annex II of this Transfer Addendum and the Customer's actual use of the Services.

Technical and organisational measures are supplied by the Security Policy / Security Addendum and DPA.

Relevant Subprocessor information is supplied by the current BACI Subprocessor Policy & List.

Where additional information is legally required to complete the SCCs, the applicable Agreement, Order or transfer record will supply it.

9. EU SCC OPTIONAL CLAUSES

For Modules Two and Three, BACI uses general written authorisation for Subprocessors, subject to the notice and objection process in the DPA and Subprocessor Policy & List.

The optional docking clause may apply where appropriate to permit an eligible entity to accede to the SCCs.

The optional independent dispute-resolution language in Clause 11 will not apply unless expressly agreed or required.

The parties will make other SCC selections only as permitted by the official clauses.

10. EU SCC GOVERNING LAW AND COURTS

Where the EU SCCs require selection of an EU Member State's law and courts, the parties select the Netherlands unless an applicable Order identifies another eligible Member State.

This selection applies only to the SCC provisions requiring an EU Member State law or forum and does not replace the Agreement's general governing-law and dispute provisions for matters outside the SCCs.

The selected law must permit third-party beneficiary rights required by the SCCs.

11. UNITED KINGDOM RESTRICTED TRANSFERS

Where UK data-protection law requires appropriate safeguards for a Restricted Transfer, BACI and Customer may use the UK Addendum together with the EU SCCs or another legally valid UK transfer mechanism.

The EU SCCs alone are not treated as sufficient for a UK Restricted Transfer where UK law requires the UK Addendum, IDTA or another recognised safeguard.

The applicable UK mechanism is incorporated as described in Annex III.

12. UK DATA PROTECTION TEST / TRANSFER ASSESSMENT

Where UK law requires a transfer risk assessment or data protection test, the responsible party will assess, acting reasonably and proportionately, whether the standard of protection for the transferred information will remain at the level required by UK law after the transfer.

BACI will provide information reasonably available to it and reasonably necessary for Customer to complete a Customer-required assessment concerning BACI's Services.

Where additional protections are necessary, the parties will implement appropriate Supplementary Measures where reasonably practicable.

13. OTHER JURISDICTIONS

Where another jurisdiction requires contractual or other safeguards for an international transfer, the parties will use a legally valid mechanism applicable to that jurisdiction.

BACI may publish a regional transfer schedule implementing country-specific requirements.

Where a jurisdiction lawfully permits adaptation of the EU SCCs or another recognised model, the parties may use the adapted mechanism to the extent permitted.

Nothing in this Transfer Addendum represents that one transfer instrument automatically satisfies every jurisdiction.

14. TRANSFER ASSESSMENTS

BACI will conduct, support or document Transfer Assessments where required by Applicable Data Protection Law and BACI's role in the relevant transfer.

An assessment may consider the categories and sensitivity of Personal Data; purpose and duration; destination; Data Importer; technical architecture; encryption; remote access; onward transfers; government-access laws and practices; practical experience where legally relevant; contractual protections; available remedies; and Supplementary Measures.

Transfer Assessments may be reviewed when material circumstances change.

15. CUSTOMER TRANSFER ASSESSMENTS

Where Customer is legally responsible for its own Transfer Assessment, BACI will provide reasonable information concerning BACI's relevant Processing, security controls, Subprocessors and transfer mechanisms, subject to confidentiality and security restrictions.

Customer remains responsible for evaluating Customer-specific purposes, data categories, legal requirements and transfer circumstances outside BACI's knowledge or control.

BACI is not responsible for Customer's legal conclusion solely because BACI provides supporting information.

16. SUPPLEMENTARY TECHNICAL MEASURES

Depending on transfer risk and architecture, Supplementary Measures may include encryption in transit and at rest, access restrictions, tenant isolation, pseudonymisation, data minimisation, key-management controls, regional processing, restricted support access, logging, monitoring or other technical protections.

No single technical measure is guaranteed to eliminate all transfer risk.

The appropriate measure depends on the data, threat model, Processing purpose and legal requirement.

17. SUPPLEMENTARY CONTRACTUAL MEASURES

BACI may use contractual measures including purpose restrictions, confidentiality, security obligations, government-request procedures, onward-transfer restrictions, audit rights, deletion obligations, incident requirements and commitments to challenge or narrow certain government requests where lawful and appropriate.

Contractual measures supplement but do not replace technical measures where the applicable legal assessment requires technical protection.

18. SUPPLEMENTARY ORGANISATIONAL MEASURES

Organisational measures may include access governance, personnel confidentiality, security training, incident response, transfer review, legal-request procedures, Subprocessor oversight, retention controls and documented escalation.

BACI may revise organisational measures as its Services and risk environment evolve, provided applicable transfer protections are maintained.

19. ENCRYPTION

BACI will use encryption or equivalent protective controls appropriate to the risk for Customer Personal Data transmitted over public networks and for protected Customer Personal Data stored within applicable production systems where technically appropriate.

Where encryption is relied upon as a material Supplementary Measure, BACI will consider relevant key access, administrative access and technical architecture.

BACI will not claim that encryption makes lawful government access impossible where that conclusion is not factually supported.

20. DATA MINIMISATION FOR TRANSFERS

BACI will seek to limit international transfer and remote access to Personal Data reasonably necessary for the applicable Service, support, security, resilience, legal or operational purpose.

Where practicable, BACI may use aggregated, de-identified, pseudonymised or otherwise minimised information instead of directly identifiable information.

Data minimisation does not require BACI to impair contracted functionality where the relevant Processing is lawful and necessary.

21. REMOTE ACCESS

Remote access from another country may constitute a Restricted Transfer under applicable law.

BACI will evaluate remote administrative, support and engineering access according to applicable transfer requirements and security controls.

The fact that data remains physically hosted in one region does not necessarily mean no international transfer occurs if persons in another jurisdiction can access the Personal Data.

22. SUBPROCESSOR TRANSFERS

BACI may engage Subprocessors in other countries in accordance with the DPA and Subprocessor Policy & List.

Where BACI makes a Restricted Transfer to a Subprocessor, BACI will implement an applicable lawful transfer mechanism and require appropriate downstream protections.

BACI will not treat Customer's general Subprocessor authorisation as a waiver of mandatory transfer-law requirements.

23. ONWARD TRANSFERS

A Data Importer may make onward transfers only where permitted by the applicable transfer instrument, Agreement and Applicable Data Protection Law.

Where the EU SCCs apply, onward transfers are governed by the applicable SCC requirements.

BACI will require relevant Subprocessors to impose appropriate protections on their downstream processors where required.

24. AI PROVIDERS AND INTERNATIONAL TRANSFERS

Where a third-party AI provider Processes Customer Personal Data on BACI's behalf across borders, BACI will evaluate the provider as a Subprocessor and apply applicable transfer safeguards.

BACI will not make unsupported claims concerning an AI provider's retention, training, geographic processing or government-access practices.

International transfer does not alter BACI's no-general-model-training-by-default commitment.

25. DATA RESIDENCY

A data-residency configuration may reduce certain transfer paths but does not by itself establish that no Restricted Transfer occurs.

Support access, security operations, resilience, Subprocessors and Customer-selected integrations may create additional Processing locations.

BACI will not promise exclusive in-region Processing unless the applicable Order or Supplemental Terms expressly provide that commitment.

26. GOVERNMENT ACCESS REQUESTS

If BACI receives compulsory governmental or law-enforcement process seeking transferred Customer Personal Data, BACI will assess the request under Applicable Law, the Agreement and applicable transfer instrument.

Where legally permitted and reasonably practicable, BACI will notify Customer before disclosure.

BACI may seek clarification, narrowing or legal review of a request BACI reasonably believes is unlawful, defective or materially overbroad.

BACI will not voluntarily provide unrestricted access to Customer environments merely because a government authority makes an informal request.

27. DISCLOSURE MINIMISATION

Where BACI determines that disclosure to a public authority is legally required, BACI will seek to disclose only the information reasonably required by the valid legal demand.

Where permitted, BACI may use procedural and legal mechanisms to protect Customer confidentiality and Data Subject rights.

Nothing in this provision requires BACI to obstruct lawful process.

28. GOVERNMENT ACCESS TRANSPARENCY

BACI may publish transparency information concerning government requests where lawful and operationally appropriate.

BACI will not publish invented request statistics or represent that BACI has never received a particular category of request unless BACI has verified that statement.

Where law prohibits disclosure of a specific request, BACI will comply with the applicable restriction while preserving any lawful right to challenge it.

29. LEGAL CHALLENGES

Where a government request materially affects transferred Customer Personal Data and BACI has reasonable grounds to believe the request is unlawful, defective or materially overbroad, BACI may challenge, narrow or seek review of the request where legally permissible and reasonably appropriate.

The applicable SCCs or other mandatory transfer instrument govern any stronger challenge obligation.

BACI is not required to pursue a legally unavailable or manifestly futile remedy.

30. DATA SUBJECT RIGHTS

Restricted Transfers do not reduce Data Subject rights under Applicable Data Protection Law.

BACI will provide assistance with Data Subject requests according to the DPA where BACI acts as Processor.

Where a mandatory transfer instrument gives Data Subjects third-party beneficiary rights, those rights apply according to that instrument.

31. SECURITY INCIDENTS

A Security Incident involving transferred Customer Personal Data will be handled under the DPA and Security Policy / Security Addendum.

Where a transfer instrument imposes additional incident obligations, those mandatory obligations apply.

The existence of an international transfer does not reduce BACI's security obligations.

32. RETENTION AND DELETION

Transferred Customer Personal Data remains subject to the DPA, Data Retention & Deletion Policy, Customer instructions and Applicable Data Protection Law.

International transfer does not create an independent right to retain data indefinitely.

Subprocessors receiving transferred data are subject to applicable deletion or return obligations.

33. DOCUMENTATION

BACI will maintain documentation reasonably necessary to demonstrate compliance with transfer obligations applicable to BACI.

Documentation may include transfer records, SCC implementation information, Subprocessor records, Transfer Assessments, security information and legal-request procedures.

BACI may protect privileged, security-sensitive, provider-confidential and unrelated Customer information.

34. CUSTOMER INFORMATION REQUESTS

Eligible Customers may request reasonable information necessary to evaluate BACI's applicable transfer safeguards.

BACI may satisfy requests through the DPA, this Transfer Addendum, Security Addendum, Subprocessor Register, transfer-assessment summaries, contractual documentation or other appropriate materials.

BACI is not required to disclose information that would compromise security, privilege, another Customer's confidentiality or Applicable Law.

35. REGULATORY COOPERATION

BACI will cooperate with competent supervisory authorities as required by Applicable Data Protection Law and applicable transfer instruments.

Where a regulator requires information concerning a Customer-specific transfer, BACI may coordinate with Customer where legally permitted and appropriate.

Nothing in this provision transfers Customer's independent regulatory obligations to BACI.

36. SUSPENSION OF TRANSFERS

BACI may suspend a Restricted Transfer where BACI reasonably determines that the applicable transfer mechanism is no longer valid, required protections cannot be maintained, or continuing the transfer would violate Applicable Law.

Where reasonably practicable, BACI will seek an alternative lawful mechanism or configuration before materially disrupting the Services.

Customer may be required to discontinue affected Processing where no lawful transfer basis remains.

37. INVALIDATED OR REPLACED TRANSFER MECHANISMS

If a transfer mechanism is invalidated, repealed, replaced or materially amended, the parties will cooperate to implement a valid successor mechanism where necessary.

Where Applicable Law automatically recognises an updated version of a transfer instrument, the updated instrument may apply according to its terms.

BACI may amend this Transfer Addendum to operationalise a lawful replacement, provided mandatory protections are not reduced.

38. CERTIFICATIONS AND FRAMEWORKS

BACI may rely on an approved certification, code of conduct, privacy framework or similar transfer mechanism only where Applicable Data Protection Law recognises it and BACI or the relevant recipient has actually obtained and maintains the status necessary for reliance.

BACI will not claim participation in the EU-U.S. Data Privacy Framework, UK Extension, Swiss-U.S. Data Privacy Framework, Binding Corporate Rules or any comparable programme unless the relevant participation is verified and legally effective.

If BACI later obtains such status, BACI may add it as an available transfer basis without eliminating other safeguards that remain contractually required.

39. DEROGATIONS

Where Applicable Data Protection Law permits a Restricted Transfer through a specific derogation or exception, the responsible party may rely on it only where its legal conditions are satisfied.

Derogations intended for occasional or exceptional transfers will not be treated as a routine substitute for appropriate safeguards where law does not permit that use.

40. CUSTOMER-INITIATED TRANSFERS

Customer is responsible for transfer-law compliance concerning destinations, integrations or recipients independently selected by Customer where BACI merely executes Customer's lawful instruction and the recipient is not BACI's Subprocessor.

BACI remains responsible for its own obligations in transmitting the information securely and following lawful instructions.

Customer may not instruct BACI to make a transfer Customer knows or reasonably should know is unlawful.

41. PUBLIC-SECTOR TRANSFERS

Government and public-sector Customers may be subject to additional localisation, sovereignty, procurement or transfer restrictions.

Such requirements apply only where established by Applicable Law or expressly incorporated through the Government & Public Sector Schedule, Order or Supplemental Terms.

BACI will not represent that an ordinary commercial environment satisfies sovereign-cloud, classified-data or government-localisation requirements unless factually and contractually established.

42. REGULATED DATA

Specially regulated data may require additional transfer restrictions.

Customer must not submit classified or specially restricted data to an ordinary BACI environment unless BACI has expressly authorised the environment for that category.

Where BACI agrees to support a regulated transfer, additional safeguards may be specified in an Order or Supplemental Terms.

43. CONFLICT WITH LOCAL LAW

If BACI reasonably believes that laws or practices applicable to a Data Importer prevent compliance with a mandatory transfer instrument, BACI will assess the issue as required by Applicable Data Protection Law.

BACI may implement Supplementary Measures, suspend the transfer, change the Processing location, replace a Subprocessor or take another lawful measure.

The applicable mandatory transfer instrument controls any required notification to Customer or a supervisory authority.

44. TRANSFER MONITORING

BACI may monitor material legal and operational developments affecting its transfer mechanisms, including adequacy decisions, SCC guidance, UK transfer rules, material Subprocessor changes and relevant court or regulatory decisions.

BACI will reassess a transfer where required by law or where a material change reasonably calls the existing assessment into question.

45. NO ABSOLUTE TRANSFER-RISK GUARANTEE

BACI will implement safeguards required by the Agreement and Applicable Law, but no contractual or technical framework can guarantee elimination of every cross-border legal or governmental-access risk.

This provision does not reduce BACI's obligation to conduct required assessments or implement legally necessary protections.

46. CUSTOMER RESPONSIBILITIES

Customer is responsible for identifying Customer-specific transfer requirements; providing accurate information about Customer's role and Processing; selecting appropriate Service configurations; evaluating Customer-selected recipients; complying with Customer's own transparency and legal-basis obligations; and avoiding unlawful transfer instructions.

Where Customer acts as Processor for another Controller, Customer is responsible for ensuring it has authority to appoint BACI as Subprocessor and to authorise applicable transfers.

47. LIABILITY

Liability arising under this Transfer Addendum is governed by the Agreement, including applicable exclusions, limitations and enhanced caps, except to the extent a mandatory transfer instrument or Applicable Law provides rights that cannot lawfully be limited.

This Transfer Addendum does not create a separate duplicative liability cap.

48. TERM AND SURVIVAL

This Transfer Addendum applies for as long as BACI or an authorised recipient Processes Personal Data subject to a Restricted Transfer under the Agreement.

Transfer protections that by their nature must continue after termination survive for as long as the relevant transferred Personal Data remains subject to them.

49. CHANGES

BACI may update this Transfer Addendum to reflect changes in transfer law, regulatory guidance, approved instruments, adequacy decisions, Services, Processing architecture or Subprocessors.

BACI will not use an update to reduce a mandatory protection or invalidate an incorporated transfer instrument.

Where a material change requires Customer action, BACI will provide appropriate notice where required by the Agreement or Applicable Law.

50. INTERPRETATION AND PRECEDENCE

If this Transfer Addendum conflicts with the EU SCCs, UK Addendum, IDTA or another mandatory transfer instrument applicable to a particular Restricted Transfer, the mandatory instrument controls for that transfer.

For matters not governed by a mandatory transfer instrument, the Agreement's order of precedence applies.

Nothing in this Transfer Addendum creates a representation that a transfer is lawful where the legal conditions for the selected mechanism are not satisfied.

51. CONTACT

International-transfer and privacy enquiries may be directed to:

BACI Privacy BACI LLC privacy@bacihq.com

Security matters may be directed to:

security@bacihq.com

ANNEX I — EU STANDARD CONTRACTUAL CLAUSES IMPLEMENTATION

1. Incorporation

Where required, the EU SCCs adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference into the Agreement.

2. Modules

Module One: Controller to Controller, where legally applicable. Module Two: Controller to Processor. Module Three: Processor to Processor. Module Four: Processor to Controller, where legally applicable.

Only the module corresponding to the parties' actual roles for the relevant transfer applies.

3. Clause 7

The optional docking clause applies where an eligible additional entity accedes in accordance with the SCCs.

4. Clause 9

For Modules Two and Three, Option 2 — general written authorisation — applies. The notice period and objection mechanism are those stated in the DPA or applicable Subprocessor notice.

5. Clause 11

The optional independent dispute-resolution language does not apply unless expressly agreed.

6. Clause 17

Option 1 applies. The governing law is the law of the Netherlands unless another eligible EU Member State is specified in the applicable Order.

7. Clause 18

The competent courts are the courts of the Netherlands unless another eligible EU Member State is specified in the applicable Order.

8. Annex I.A — Parties

The Data Exporter and Data Importer are identified in the Agreement, applicable Order and relevant transfer relationship. Contact details are those maintained in the parties' contractual records.

9. Annex I.B — Description of Transfer

The categories of Data Subjects, categories of Personal Data, sensitive data, frequency, nature, purpose, duration and retention are described in the DPA, Annex II of this Transfer Addendum, applicable Order and Customer's actual use of the Services.

10. Annex I.C — Supervisory Authority

The competent supervisory authority is determined under Clause 13 of the applicable SCC module.

11. Annex II — Technical and Organisational Measures

The applicable measures are described in the BACI Security Policy / Security Addendum and DPA.

12. Annex III — Subprocessors

The current BACI Subprocessor Policy & List supplies applicable Subprocessor information for Modules Two and Three.

13. Conflict

The official EU SCC text controls over any inconsistent summary or completion language in this Annex.

ANNEX II — TRANSFER DESCRIPTION

A. Subject Matter

International Processing of Personal Data as necessary to provide, operate, secure, support, maintain and administer the BACI Services and perform the Agreement.

B. Data Subjects

Depending on Customer use: Customer personnel, Authorised Users, administrators, contractors, customers, prospective customers, suppliers, partners, professional contacts, investors, funders, applicants and other individuals whose Personal Data is lawfully Processed through the Services.

C. Personal Data

Depending on Customer use: identity and contact information; professional and organisational information; account and user information; communications; commercial information; business-contact information; Customer-provided content; transaction-related information; technical, device, usage and interaction information; integration data; and other Personal Data lawfully submitted by Customer.

D. Sensitive Data

Special-category or specially regulated data is not intended for ordinary BACI environments unless BACI expressly authorises the relevant Service or environment. Additional safeguards may apply where authorised.

E. Frequency

Continuous, periodic or Customer-initiated depending on Service and configuration.

F. Nature and Purpose

Hosting, storage, retrieval, analysis, transformation, transmission, support, security, monitoring, reporting, automation, AI-enabled processing, integration functionality, opportunity discovery, forecasting and other Customer-requested Services.

G. Duration

For the applicable Service term and thereafter only for lawful retention, deletion, backup, security and legal purposes under the Agreement.

H. Processing Locations

Determined by the applicable BACI Service architecture, Customer configuration and current Subprocessor Register. A listed provider or region does not imply use for every Customer.

I. Retention

Governed by the DPA, Data Retention & Deletion Policy, Customer instructions, applicable Order and Applicable Law.

ANNEX III — UNITED KINGDOM TRANSFER IMPLEMENTATION

1. Approved UK Mechanism

Where a UK Restricted Transfer requires contractual safeguards and the parties use the UK Addendum, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated by reference in its legally effective form, as revised in accordance with its mandatory terms.

2. EU SCCs

The Approved EU SCCs are the SCCs incorporated and completed under Annex I of this Transfer Addendum.

3. Parties

The Exporter and Importer are the parties identified in the Agreement and relevant transfer relationship.

4. Appendix Information

The information required for the applicable SCC appendices is supplied by the Agreement, DPA, Security Policy / Security Addendum, Subprocessor Policy & List, Annex I and Annex II of this Transfer Addendum.

5. Mandatory Clauses

The mandatory clauses of the Approved UK Addendum apply without modification except to the extent the official instrument permits.

6. Updated UK Instruments

If the Information Commissioner revises the Approved Addendum or another lawful UK mechanism replaces it, the parties may rely on the updated mechanism according to Applicable Law and the instrument's transition rules.

7. Data Protection Test

The responsible exporter will complete the assessment or data protection test required by UK law and implement additional protections where necessary.

8. Conflict

The official Approved UK Addendum controls over inconsistent language in this Transfer Addendum for the applicable UK Restricted Transfer.

ANNEX IV — TRANSFER ASSESSMENT FRAMEWORK

A Transfer Assessment may consider:

1. identities and roles of exporter and importer; 2. categories and sensitivity of Personal Data; 3. volume, frequency and duration; 4. purpose and necessity of the transfer; 5. destination country and relevant legal framework; 6. nature of the recipient and its access; 7. onward-transfer paths; 8. hosting and remote-access locations; 9. encryption and key-access architecture; 10. pseudonymisation and minimisation; 11. contractual restrictions; 12. security controls; 13. government-access laws and practices; 14. legally relevant practical experience and transparency information; 15. available judicial or administrative remedies; 16. Subprocessor dependencies; 17. retention and deletion; 18. Supplementary Measures; 19. material changes since the previous assessment; and 20. whether the required legal standard remains satisfied.

The assessment will be reasonable and proportionate to the transfer and Applicable Data Protection Law.

ANNEX V — TRANSFER MECHANISM HIERARCHY

For a Restricted Transfer, BACI will identify an available lawful basis in the following functional order where appropriate:

1. applicable Adequacy Decision or equivalent recognition; 2. approved contractual safeguards such as EU SCCs, UK IDTA or UK Addendum; 3. verified binding corporate rules, approved certification or code mechanism where legally available and actually applicable; 4. another specifically authorised or legally recognised safeguard; or 5. a lawful derogation or exception where its conditions are satisfied.

This hierarchy is operational guidance and does not override Applicable Data Protection Law. A mechanism higher in the list is not mandatory where another lawful mechanism is more appropriate for the transfer.

BACI INTERNATIONAL DATA TRANSFER ADDENDUM — VERSION 1.0 Effective 10 September 2026

We're listening.