Data Processing Agreement Effective: 4 October 2026. 1. Scope and roles. This DPA applies to personal data contained in the Client's submitted source code, benchmark inputs, execution results and other project materials (Project Personal Data). The Client acts as controller, or as a processor authorised by its controller; the Provider acts as processor or sub-processor respectively. For account administration, sign-in, billing, fraud prevention and its own legal obligations the Provider acts as controller, as described in the Privacy Notice. Data protection law means the UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR. Confidential information that is not personal data is protected by the NDA. 2. Processing particulars. Processing comprises receipt, storage, compilation, execution, testing, measurement, optimisation, preparation and delivery of results, and deletion, solely for the services the Client orders, for the service period and the retention period under clause 4. Before any upload, the project records in the dashboard whether its materials are intended to contain personal data and, if so, whose and what. The Client determines those contents and the purpose, maintains the necessary authority and lawful basis, and gives its documented instructions through the order and the dashboard. Special-category data and data about criminal offences require a separate written processing schedule agreed before upload. The Provider does not use Project Personal Data for its own purposes or for other clients. 3. Security. 3.1. Client code is executed only in single-use virtual machines without network access, on an application server that ABX DEVELOPMENT LLP operates with its host infrastructure in Lithuania; the service's main database is held on that server, and the project keys in a separate key database on a separate data server that ABX DEVELOPMENT LLP operates there. No separate hosting provider processes account or project contents on either server. 3.2. Submitted project materials are encrypted at rest with a separate key for each project; stored project keys are encrypted under a master key. Account credentials and financial records are protected appropriately to their separate storage and purposes. 3.3. The action log records account, project and operational metadata needed for accountability; it is append-only and does not intentionally record submitted source code or benchmark contents. 3.4. Access by the Provider's personnel is limited to what their assigned duties require, under confidentiality duties. 4. Retention and deletion. The dashboard shows the project's default retention date, normally 30 days after creation. Automatic deletion of project materials from active storage and removal of the wrapped project key from the active key database record take place at the next scheduled maintenance cycle after that date, except while the materials remain necessary for a queued or running task ordered by the Client or for an unresolved trial, decline or challenge. Such continued retention is limited to that purpose and ends when it is no longer necessary; an abandoned task or dispute does not justify indefinite retention, and once the work or procedure ends, overdue materials are deleted at the next maintenance cycle. The Client may give an earlier deletion instruction by deleting the project in the dashboard. Any separately agreed extension is recorded for the project. Project files retained on the application server's persistent storage are encrypted, under a separate key for each project. Project keys are persistently stored only in wrapped form in the key database on the separate data server, and are not included in any snapshot or backup. Deletion removes the wrapped project key from the active key database record. The Provider completes removal of residual copies of the deleted project's key from the key database files within 24 hours after removal from the active key database record. Completion is recorded only after the key-table rewrite and transaction-log cleanup have removed those copies, including earlier row versions retained for ongoing transactions. After completion, no database file, snapshot or backup held by the Provider contains a copy of that project's key; storage blocks released by these deletions are not separately overwritten, and the Provider does not guarantee their physical erasure. Encrypted project files may remain in snapshots and backups of the application server until those are replaced in their regular rotation, within 7 days; such copies are kept beyond operational use and are never restored to service, and if the application server is restored from a snapshot or backup, projects deleted since it was taken are deleted again, with their files, before public access or user-job processing resumes; the restored service remains in maintenance isolation until the required project and file deletions have been completed. Working copies of project materials made during processing are held in memory only: the memory of the processes that handle project materials or keys is excluded from swap and from memory dumps, and snapshots and backups of the servers do not include memory. Records of orders, delivery checksums, payments and security events are kept separately for the purposes and periods stated in the Privacy Notice; they do not include submitted source code or benchmark contents. 5. Recipients, sub-processors and transfers. Compilation and execution of Client code take place on the Provider's own server in Lithuania. Network delivery is separate: Cloudflare terminates TLS and processes traffic to deliver and protect the service under its data processing terms. For dashboard upload requests, project file contents and file names are encrypted in the Client's browser using the Provider's transit public key before transmission. The dashboard enables file uploads only after its encryption handler is ready and does not transmit a file if encryption cannot be completed. The Provider rejects file uploads that do not use this encrypted format. For downloads of delivered builds, the dashboard sends with the request a one-time public key generated in the Client's browser; the Provider encrypts the build and its file name to that key, and the browser decrypts them. The Provider refuses download requests without such a key. This protection depends on the dashboard page, its script, the response supplying the Provider's transit public key and the browser's download key reaching their destination unaltered; all are carried through Cloudflare. It does not protect against active modification of that delivery path. Other traffic, including dashboard pages displaying file names, sizes and checksums, sign-in data and reports, passes through Cloudflare in readable form. The Provider does not promise that Cloudflare never retains transit or security data. The Recipients Schedule (taktcycles.com/legal/recipients.html) identifies each recipient, its role, the data, the purposes, the locations and the safeguards for transfers. Email notifications contain no source code or benchmark contents. The Client authorises the sub-processors named in the schedule. The Provider gives at least 30 days' notice by email of an addition or replacement and a reasonable opportunity to object on data-protection grounds before the affected processing begins; an objection that cannot be resolved is met by an alternative arrangement or by termination of the affected service with a refund of unused prepaid charges. Each sub-processor is bound by equivalent data-protection obligations, and the Provider remains responsible to the Client for their performance. A server rented for a referee measurement under the Trial Agreement is used only after it has been added to the schedule for that order with the Client's agreement and with the safeguard the transfer requires. 6. Instructions and confidentiality. The Provider follows the Client's documented instructions, including on international transfers. If law requires other processing, the Provider informs the Client beforehand unless the law prohibits it, and it promptly tells the Client of an instruction it considers unlawful. The Provider's personnel are bound by confidentiality duties. 7. Assistance and breaches. The Provider maintains measures appropriate to the risks under Article 32 of the UK GDPR and regularly evaluates them. Taking into account the processing and the information available to it, it assists the Client with requests from individuals, security, breach notifications, impact assessments and prior consultation under Articles 32 to 36. It notifies the Client without undue delay after becoming aware of a personal data breach affecting Project Personal Data, provides the information available and supplements it as the investigation proceeds. 8. End of processing. At the Client's choice, the Provider returns all Project Personal Data held for the Client in an agreed accessible format, including relevant execution results, or deletes it at the end of the processing service, and deletes remaining copies under clause 4. This does not transfer rights in, or require delivery of, unrelated optimisation methods or source code. Any retention required by law is limited to that requirement, disclosed where permitted and protected against other use. 9. Verification. The Provider provides the information needed to demonstrate compliance and allows and contributes to audits, including inspections, by the Client or an auditor mandated by it, under proportionate confidentiality, access and scheduling safeguards. These safeguards may protect other clients and the Provider's unrelated optimisation know-how, but may not prevent verification required by law. An audit confers no right to the optimiser or to transformed source code. 10. The Client may at any time delete a project in the dashboard and request an export of the action log for its projects.