BACI

SUBPROCESSORS

Version 1.0

BACI SUBPROCESSOR POLICY & LIST

Version 1.0

Effective Date: 10 September 2026

Last Updated: 10 September 2026

This Subprocessor Policy & List ("Policy") describes how BACI LLC ("BACI") selects, authorises, governs, monitors and changes third parties that Process Customer Personal Data on BACI's behalf in connection with the Services.

BACI uses a contractual and risk-based Subprocessor framework. BACI does not designate a company as a Subprocessor merely because BACI purchases a product or service from that company. A third party is treated as a Subprocessor for purposes of this Policy when it Processes Customer Personal Data on BACI's behalf in providing the applicable Services and the relationship falls within the relevant definition under Applicable Data Protection Law.

The current Subprocessor Register is maintained in Annex I. BACI will not populate that Register with assumed, proposed or merely possible providers. A provider will be listed when BACI has verified the relevant legal entity, Processing function and applicable Processing location information.

1. SCOPE

This Policy applies to Subprocessors engaged by BACI to Process Customer Personal Data on behalf of Customers in connection with the Services.

It does not automatically apply to independent third parties chosen or controlled by Customer, third-party services to which Customer independently directs data, payment providers acting as independent controllers for their own purposes, professional advisers acting under independent legal duties, or vendors that do not Process Customer Personal Data on BACI's behalf.

The legal role of a third party is determined by the actual Processing relationship and Applicable Data Protection Law, not by its commercial label.

2. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

This Policy forms part of the BACI Legal Framework and should be read with the Terms of Service, Privacy Policy, Data Processing Addendum ("DPA"), Security Policy / Security Addendum, Data Retention & Deletion Policy, International Data Transfer Addendum and applicable Orders and Supplemental Terms.

For Customer Personal Data Processed by BACI on Customer's behalf, the DPA is authoritative regarding BACI's Subprocessor obligations. This Policy implements and explains that framework and maintains the applicable Subprocessor Register.

If an executed Agreement imposes a different or additional Subprocessor requirement, the applicable order of precedence controls.

3. DEFINITION OF SUBPROCESSOR

A "Subprocessor" is a third party engaged by BACI that Processes Customer Personal Data on BACI's behalf in connection with the Services.

A Subprocessor may provide infrastructure, hosting, storage, database, networking, communications, authentication, support, security, artificial-intelligence, analytics or other functionality where the provider receives or can access Customer Personal Data as BACI's processor or subprocessor.

A provider is not necessarily a Subprocessor merely because its technology is present in BACI's supply chain.

4. GENERAL AUTHORISATION

Where the DPA applies, Customer generally authorises BACI to engage Subprocessors in accordance with the DPA and this Policy.

BACI remains responsible for satisfying its applicable contractual and statutory obligations concerning Subprocessor engagement.

General authorisation does not permit BACI to disregard notice, contractual-flow-down, transfer or security requirements imposed by Applicable Data Protection Law.

5. SUBPROCESSOR DUE DILIGENCE

Before authorising a material Subprocessor to Process Customer Personal Data, BACI will conduct due diligence proportionate to the nature and risk of the Processing.

Assessment may include the provider's security programme, privacy practices, data locations, access model, incident history, certifications or independent assurance where available, contractual protections, deletion practices, business continuity, technical architecture, government-access exposure, international-transfer mechanisms and other relevant risk factors.

The depth of assessment may vary according to the sensitivity, volume, duration and consequence of the Processing.

6. CONTRACTUAL REQUIREMENTS

BACI will enter into written terms with each Subprocessor requiring protection of Customer Personal Data appropriate to the Processing.

Where required by Applicable Data Protection Law, those terms will impose data-protection obligations no less protective in substance than the obligations applicable to BACI for the relevant Processing, including appropriate confidentiality, security, Processing-purpose, assistance, deletion or return, incident, Subprocessor and international-transfer requirements.

BACI will not rely solely on a provider's public privacy policy where a processor contract is legally required.

7. CONFIDENTIALITY

BACI will require Subprocessors to ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations.

Access should be limited to personnel and systems requiring it for the authorised service.

A Subprocessor's technical ability to access Customer Personal Data does not authorise access for unrelated purposes.

8. SECURITY REQUIREMENTS

BACI will require Subprocessors to implement technical and organisational measures appropriate to the risk of their Processing.

BACI may evaluate identity and access controls, encryption, infrastructure security, vulnerability management, secure development, logging, monitoring, incident response, backup and recovery, personnel controls, business continuity and other safeguards relevant to the service.

A Subprocessor may implement controls differently from BACI provided the resulting protections satisfy the applicable contractual and legal requirements.

9. SECURITY INCIDENTS

BACI will require Subprocessors to notify BACI of relevant security incidents within a timeframe that permits BACI to meet its own contractual and legal notification obligations.

BACI remains responsible for notifying Customer of a Security Incident as required by the DPA and Agreement.

A Subprocessor incident will be evaluated according to the affected data, systems, Customers and applicable legal requirements rather than solely according to the provider's classification.

10. INTERNATIONAL PROCESSING

A Subprocessor may Process Customer Personal Data outside Customer's country where permitted by the Agreement and Applicable Data Protection Law.

Where a restricted transfer requires a lawful transfer mechanism, BACI will implement or require an applicable mechanism, which may include adequacy, Standard Contractual Clauses, the UK International Data Transfer Addendum or another legally valid mechanism.

BACI will not claim that a provider, certification, framework or adequacy status applies unless BACI has verified that it applies to the relevant Processing.

11. PROCESSING LOCATIONS

BACI will seek to identify countries or regions from which material Subprocessors store or Process Customer Personal Data where that information is relevant to Customer transparency or transfer compliance.

Processing-location disclosures may describe primary hosting regions and material remote-access locations where appropriate.

A provider's global corporate presence does not mean Customer Personal Data is Processed in every country in which that provider operates.

12. DATA RESIDENCY

Where Customer has contracted for a specific BACI data-residency configuration, BACI will select and configure relevant Subprocessors consistently with that contractual commitment, subject to expressly disclosed exceptions.

A provider's inclusion on the general Subprocessor Register does not mean every BACI Customer's data is processed by that provider or in every listed location.

Service-specific applicability may depend on Customer configuration, region, product, integration or optional functionality.

13. AI AND MODEL PROVIDERS

A third-party AI or model provider is treated as a Subprocessor where it Processes Customer Personal Data on BACI's behalf in delivering Customer-requested functionality.

Such providers are subject to the DPA and applicable Subprocessor requirements.

BACI will not represent that a third-party AI provider offers particular retention, training, localisation, security or confidentiality commitments unless those commitments are factually and contractually applicable to BACI's use.

Use of an AI Subprocessor does not alter BACI's no-general-model-training-by-default commitment under the Terms and DPA.

14. NO GENERAL MODEL TRAINING BY DEFAULT

BACI will not authorise a Subprocessor to use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other customers where BACI itself is prohibited from doing so under the Agreement.

Unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, BACI's Subprocessor arrangements for relevant AI Processing must be consistent with BACI's contractual no-general-model-training-by-default commitment.

15. SUBPROCESSOR ACCESS MINIMISATION

BACI will seek to limit Subprocessor access to Customer Personal Data to the information and duration reasonably necessary for the authorised service.

Where technically and commercially appropriate, BACI may use configuration, tokenisation, encryption, access controls, regional deployment, data minimisation or other mechanisms to reduce Subprocessor exposure.

16. SUBPROCESSOR CHANGES

BACI may add, replace or remove Subprocessors as the Services, technology, infrastructure and provider relationships evolve.

BACI will update the applicable Subprocessor Register and provide notice of new Subprocessors where required by the DPA or Applicable Data Protection Law.

Removal of a provider from the Register does not necessarily mean every historical copy of data disappears immediately; applicable deletion, backup and legal-retention processes continue to govern.

17. NOTICE OF NEW SUBPROCESSORS

Where Customer is entitled to advance notice, BACI will provide notice through a reasonable mechanism before a new Subprocessor begins relevant Processing.

The notice may be delivered by email, Customer administrative interface, subscription mechanism, trust or legal page, or another contractually recognised method.

The notice should identify sufficient information for Customer to evaluate the new Subprocessor, which may include provider identity, function and Processing location.

18. CUSTOMER OBJECTIONS

Customer may object to a new Subprocessor on reasonable, documented data-protection grounds within the period specified in the DPA or applicable notice.

Customer should explain the specific data-protection concern so BACI can evaluate it.

BACI and Customer will work in good faith to identify a commercially reasonable resolution, which may include additional information, safeguards, an alternative configuration or another reasonable measure.

An objection may not be used solely to obtain unrelated commercial concessions.

19. UNRESOLVED OBJECTIONS

If BACI cannot reasonably resolve a valid Subprocessor objection and no commercially reasonable alternative is available, the parties will follow the remedy provided by the DPA or applicable Agreement.

Where the DPA permits discontinuation of a materially affected Service, any refund for prepaid unused service will be limited to the portion expressly provided by the applicable contractual terms.

An objection to one Subprocessor does not automatically terminate unrelated Services.

20. EMERGENCY SUBPROCESSOR CHANGES

BACI may need to engage or replace a Subprocessor urgently to address a security incident, provider failure, legal requirement, sanctions issue, material service disruption or other emergency.

Where advance notice is not reasonably practicable, BACI may make the necessary change and provide notice as soon as reasonably practicable where required.

Emergency engagement does not eliminate BACI's obligation to perform appropriate due diligence and contractual protection proportionate to the circumstances.

21. SUBPROCESSOR PERFORMANCE

BACI will monitor material Subprocessor relationships using processes appropriate to the risk and service.

Monitoring may include review of updated assurance materials, security notices, incident information, contractual changes, service performance, privacy changes, certifications, transfer developments and other relevant information.

BACI may require remediation or replace a provider where material risk can no longer be managed appropriately.

22. CHAIN SUBPROCESSING

Where a Subprocessor engages another processor to Process Customer Personal Data, BACI will require the Subprocessor to apply appropriate downstream data-protection obligations where required by Applicable Data Protection Law.

BACI may rely on a Subprocessor's compliant subprocessor programme where legally permissible.

The level of public detail concerning downstream providers may depend on whether they materially Process BACI Customer Personal Data and whether disclosure is contractually or legally available.

23. RESPONSIBILITY FOR SUBPROCESSORS

BACI remains responsible for the performance of its Subprocessors' applicable data-protection obligations to the extent required by the DPA, Agreement and Applicable Data Protection Law.

This responsibility does not convert every independent act of a third party into an act within BACI's contractual control.

Liability remains subject to the applicable Agreement, including its liability limitations and enhanced caps.

24. CUSTOMER-SELECTED THIRD PARTIES

A service, integration, connector, model, application or provider selected independently by Customer is not automatically a BACI Subprocessor.

Where Customer instructs BACI to transmit Customer Data to a Customer-selected third party that acts independently of BACI, Customer is responsible for authorising and evaluating that third party unless the Agreement states otherwise.

BACI's Subprocessor obligations apply only where the third party is engaged by BACI to Process Customer Personal Data on BACI's behalf.

25. PAYMENT PROVIDERS

Payment processors and financial institutions may act as independent controllers, processors or service providers depending on the transaction and legal context.

BACI will classify such providers according to the actual Processing relationship.

A payment provider will be listed as a Subprocessor only where it Processes Customer Personal Data on BACI's behalf in a manner that falls within the DPA's Subprocessor definition.

26. PROFESSIONAL ADVISERS

Lawyers, accountants, auditors, insurers and other professional advisers may process information under independent professional, legal or regulatory duties.

Such advisers are not automatically Subprocessors.

Where an adviser acts as BACI's processor for Customer Personal Data rather than under an independent role, BACI will apply the appropriate processor requirements.

27. TELECOMMUNICATIONS AND NETWORK PROVIDERS

Internet carriers, telecommunications networks and other entities that merely transmit data without acting as BACI's processor may not constitute Subprocessors under Applicable Data Protection Law.

BACI will not inflate the Subprocessor Register by listing every entity through whose infrastructure network traffic may technically pass.

28. SUPPORT PROVIDERS

A support or customer-service provider will be treated as a Subprocessor where it can access or Process Customer Personal Data on BACI's behalf.

BACI will seek to restrict support access according to role, purpose and need.

Where a provider supplies only tooling and does not receive Customer Personal Data, it need not be listed solely because BACI uses the tool.

29. SECURITY PROVIDERS

Security providers may qualify as Subprocessors where they receive or Process Customer Personal Data, such as logs, identifiers or security-event information, on BACI's behalf.

BACI will assess the data involved and classify the relationship accordingly.

Security telemetry will not be treated as outside data-protection requirements merely because its primary purpose is cybersecurity.

30. INFRASTRUCTURE AND HOSTING PROVIDERS

Cloud, database, storage, hosting and managed-infrastructure providers that store or Process Customer Personal Data for BACI generally qualify as Subprocessors.

BACI will assess their security, contractual protections, Processing locations, resilience and applicable transfer mechanisms.

BACI may use more than one infrastructure provider, and applicability may vary by Service, Customer region or architecture.

31. COMMUNICATION PROVIDERS

Email, messaging, notification and communications providers may qualify as Subprocessors where they Process Customer Personal Data on BACI's behalf.

BACI will distinguish operational communications from providers acting independently for their own purposes.

Only providers actually used for relevant Customer Personal Data Processing will be included in the Register.

32. ANALYTICS PROVIDERS

Analytics providers qualify as Subprocessors where they Process Customer Personal Data on BACI's behalf.

BACI will not classify optional advertising or independent third-party tracking as ordinary processor analytics merely to avoid applicable privacy obligations.

Website-cookie and advertising relationships are also governed by the Privacy Policy and Cookie Policy.

33. AUTHENTICATION AND IDENTITY PROVIDERS

Identity, authentication and access-management providers may qualify as Subprocessors where they Process Customer Personal Data for BACI-controlled authentication or account functionality.

Where Customer supplies and controls its own identity provider, that provider may instead be Customer-selected and outside BACI's Subprocessor relationship.

34. DATA DELETION AT END OF SERVICE

BACI will require relevant Subprocessors to return or delete Customer Personal Data when their Processing is no longer required, subject to lawful retention and applicable technical backup cycles.

Subprocessor deletion is governed by the DPA, Data Retention & Deletion Policy and applicable provider contract.

A provider may retain data where law independently requires it, provided such retained data remains protected and is not used for unrelated purposes.

35. BACKUPS AT SUBPROCESSORS

Customer Personal Data may remain in protected Subprocessor backups after deletion from active systems where immediate deletion is not technically practicable.

BACI will require applicable protections during the backup-retention period.

Backup copies must not be restored to ordinary active use in a manner that defeats a completed deletion obligation.

36. GOVERNMENT ACCESS RISK

BACI may consider governmental-access laws and practices relevant to international Processing and transfer-risk assessment.

Where required, BACI may implement contractual, technical or organisational supplementary measures.

BACI will not represent that use of a particular Subprocessor eliminates all government-access risk.

37. REGULATED DATA

BACI will not use a Subprocessor for specialised regulated or classified Customer Data unless the relevant BACI Service is authorised for that data and the Subprocessor arrangement is consistent with applicable contractual and regulatory requirements.

A provider's general compliance claim does not establish that BACI's specific deployment is authorised for a regulated use.

38. PUBLIC-SECTOR PROCESSING

Government and public-sector Services may use a restricted or specialised Subprocessor set under an applicable Government & Public Sector Schedule or Order.

A provider available in BACI's commercial environment is not automatically approved for a government or regulated environment.

BACI will not claim government-cloud or sovereign-cloud availability unless the relevant environment actually supports it.

39. SERVICE-SPECIFIC SUBPROCESSORS

Some Subprocessors may apply only to particular BACI Services, optional features, regions or integrations.

The Register may therefore identify an applicability field rather than implying universal use.

Customer's actual Subprocessor set may depend on the Services purchased, configured functionality and Processing region.

40. SUBPROCESSOR REGISTER CONTENT

For each listed Subprocessor, BACI will seek to publish, where applicable and reasonably available:

(a) legal entity name;

(b) service or Processing function;

(c) categories of Customer Personal Data or Processing description at an appropriate level;

(d) country or region of Processing or hosting;

(e) Service or feature applicability; and

(f) effective or addition date where useful.

BACI may provide additional information where required by Applicable Law or enterprise agreement.

41. ACCURACY OF THE REGISTER

The Subprocessor Register must reflect BACI's actual production Processing relationships.

BACI will not list a vendor merely because BACI is evaluating it, has an account with it, or may use it in the future.

BACI will not omit a material Subprocessor merely because the provider is commercially well known.

Where BACI discovers a material error in the Register, BACI will correct it within a reasonable period.

42. PROVIDER LEGAL ENTITY VERIFICATION

Before publishing a provider in the Register, BACI should verify the contracting or Processing legal entity where reasonably possible.

Brand names may be included for readability, but the legal entity should control where known.

BACI will not guess a corporate entity from a provider's brand name.

43. CHANGE HISTORY

BACI may maintain a change history recording additions, removals or material changes to the Subprocessor Register.

The change history may identify the provider, type of change, effective date and material change in Processing function or location.

Historical entries may be retained for accountability and Customer audit purposes.

44. SUBPROCESSOR NOTICE SUBSCRIPTIONS

BACI may provide a mechanism allowing Customers to subscribe to Subprocessor-change notifications.

Where such a mechanism is available, Customer is responsible for maintaining an appropriate subscription address or administrative contact.

Failure to subscribe does not eliminate a notice obligation where the Agreement requires BACI to provide notice through another specified method.

45. ENTERPRISE DUE-DILIGENCE REQUESTS

Eligible enterprise Customers may request reasonable additional information concerning material Subprocessors where necessary for privacy, security, transfer or regulatory assessment.

BACI may satisfy the request through existing documentation, assurance reports, contractual summaries or other appropriate materials.

BACI may protect provider-confidential, security-sensitive, privileged and unrelated customer information.

46. AUDIT AND ASSURANCE

BACI may use independent certifications, audit reports and provider assurance materials as part of Subprocessor oversight where relevant.

A provider's audit report may be subject to confidentiality or distribution restrictions.

BACI will not represent that a provider's audit or certification constitutes an audit or certification of BACI unless BACI is expressly within its scope.

47. SUSPENSION OR REMOVAL OF A SUBPROCESSOR

BACI may suspend new data flows to, restrict, replace or remove a Subprocessor where BACI identifies a material unresolved privacy, security, legal, sanctions, availability or contractual risk.

BACI may take emergency action without waiting for an ordinary review cycle where reasonably necessary to protect Customer Data or comply with law.

48. ACQUISITIONS AND CORPORATE CHANGES

If a Subprocessor undergoes an acquisition, merger, restructuring or other material ownership change, BACI may reassess the relationship where the change materially affects data-protection risk.

A corporate name change alone does not necessarily constitute engagement of a new Subprocessor if the relevant legal Processing relationship remains substantially unchanged.

BACI will update the Register where necessary for accuracy.

49. NO CUSTOMER OWNERSHIP TRANSFER

Use of a Subprocessor does not transfer ownership of Customer Data to the Subprocessor.

Subprocessor rights to Process Customer Personal Data are limited by the applicable contract, BACI's instructions and Applicable Data Protection Law.

BACI will not grant a Subprocessor broader rights in Customer Personal Data than BACI is entitled to grant under the Agreement.

50. CUSTOMER CONFIDENTIAL INFORMATION

Where a Subprocessor receives Customer Confidential Information in addition to Customer Personal Data, BACI will apply contractual confidentiality protections appropriate to the service.

The existence of a Subprocessor relationship does not make Customer Confidential Information public or available for the provider's unrelated commercial use.

51. SECURITY REPORTING

Security concerns relating to a BACI Subprocessor may be reported to security@bacihq.com.

BACI may investigate the concern directly or with the relevant provider.

Customers should provide sufficient information to permit BACI to identify the provider, Service and alleged risk where reasonably possible.

52. PRIVACY ENQUIRIES

Privacy and Subprocessor enquiries may be directed to privacy@bacihq.com.

BACI may require verification of Customer status before disclosing non-public enterprise information concerning a provider relationship.

53. CHANGES TO THIS POLICY

BACI may update this Policy as providers, Services, architecture, Processing locations, Applicable Data Protection Law and the BACI Legal Framework evolve.

Updates to the Subprocessor Register may occur independently of changes to the general policy text.

BACI will not use a policy update to eliminate a higher-precedence contractual notice or objection right.

54. INTERPRETATION

This Policy is intended to provide transparent and accurate information concerning BACI's Subprocessor framework.

References to a provider do not imply that every Customer uses that provider.

References to Processing locations identify relevant Processing locations to the extent reasonably known and applicable; they do not imply unrestricted transfer to every location in which a provider has personnel or infrastructure.

Nothing in this Policy authorises Processing prohibited by the DPA, Agreement or Applicable Law.

55. CONTACT

Subprocessor and privacy enquiries:

BACI Privacy BACI LLC privacy@bacihq.com

Security concerns:

security@bacihq.com

ANNEX I — CURRENT BACI SUBPROCESSOR REGISTER

BACI publishes only verified production Subprocessors in this Register.

As of the Last Updated date of this Policy, BACI has not populated this public Register with provider names that have not been verified against BACI's production architecture, applicable contracts and Processing roles.

Before a provider is entered here, BACI will verify the provider's relevant legal entity, Processing function, applicability and Processing-location information.

REGISTER FIELDS

Legal Entity / Provider: Service or Processing Function: BACI Service / Feature Applicability: Customer Personal Data Processing: Primary Processing / Hosting Location(s): International Transfer Mechanism, where applicable: Effective / Addition Date:

This verification rule prevents proposed, assumed or merely technically possible providers from being presented to Customers as current BACI Subprocessors.

Where BACI begins production Processing of Customer Personal Data through a qualifying Subprocessor, the Register will be updated in accordance with this Policy and the DPA.

ANNEX II — SUBPROCESSOR ASSESSMENT FRAMEWORK

BACI's assessment of a material Subprocessor may consider:

1. the nature and purpose of Processing; 2. categories and sensitivity of Customer Personal Data; 3. Processing volume and duration; 4. hosting and remote-access locations; 5. identity and access controls; 6. encryption and cryptographic protections; 7. vulnerability and patch management; 8. incident-response capabilities; 9. secure development and infrastructure practices; 10. backup, recovery and deletion; 11. confidentiality and personnel controls; 12. business continuity and resilience; 13. independent assurance and certifications where available; 14. downstream subprocessors; 15. international-transfer mechanisms; 16. government-access considerations; 17. provider contractual terms; 18. AI training, retention and data-use terms where relevant; 19. regulatory or sector-specific requirements; and 20. material historical or known risk information.

The assessment depth is proportionate to the risk and does not require every provider to satisfy identical technical architecture.

ANNEX III — SUBPROCESSOR CHANGE RECORD

BACI may use the following structure to record material Subprocessor changes:

Provider: Change Type: Added / Removed / Replaced / Legal Entity Change / Processing Location Change / Material Function Change Notice Date: Effective Date: Affected BACI Service or Feature: Processing Function: Processing Location: Customer Action, if any: Objection Deadline, if applicable:

A change record is historical evidence and does not override the current Subprocessor Register or applicable Agreement.

BACI SUBPROCESSOR POLICY & LIST — VERSION 1.0 Effective 10 September 2026

We're listening.