DATA PROCESSING AGREEMENT ShelfTap Version of 2026-08-01 This Agreement supplements the ShelfTap Terms of Service. Complete the Controller block, sign, and return it to legal@shelftap.com. We counter-sign and return a copy. -------------------------------------------------------------------------------- PARTIES Processor: [LEGAL ENTITY NAME — TO BE SUPPLIED] [REGISTERED ADDRESS — TO BE SUPPLIED] Registered in [COUNTRY OF INCORPORATION — TO BE SUPPLIED], number [REGISTRATION NUMBER — TO BE SUPPLIED] Controller: ______________________________________________ (legal name) ______________________________________________ (registered address) ______________________________________________ (registration number) ______________________________________________ (data protection contact) -------------------------------------------------------------------------------- 1. ROLES For personal data the Controller submits to, or generates through, the ShelfTap service, the Controller is the controller and the Processor is the processor. For the Processor's own account, billing and public-source directory data, the Processor acts as an independent controller and this Agreement does not apply. That processing is described in the ShelfTap Privacy Policy and in the KVKK/GDPR legal-basis note. 2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE Subject matter: operation of a business-to-business company discovery service. Duration: the term of the subscription, plus the retention windows published at /legal/data-retention. Nature: storage, retrieval, structuring, analysis and export of company records and search results; transactional email; payment metadata handling. Purpose: delivering the service the Controller has subscribed to. 3. CATEGORIES OF DATA SUBJECT AND PERSONAL DATA Data subjects: the Controller's own users; individuals named in publicly published company contact information. Personal data: name, business email address, business telephone number, business address, job title where published, and the source URL of each recorded fact. Excluded: special categories of personal data, criminal-offence data, and data relating to children. None are processed. 4. CONTROLLER INSTRUCTIONS The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers, unless required otherwise by law. Use of the service constitutes an instruction to process for the purposes in section 2. The Processor informs the Controller if, in its opinion, an instruction infringes applicable data protection law. 5. CONFIDENTIALITY Personnel authorised to process personal data are bound by confidentiality obligations. 6. SECURITY The Processor applies the technical and organisational measures published at /legal/security. That page also lists, explicitly, the measures the Processor does NOT claim. The Controller acknowledges it has reviewed both parts before signing. 7. SUB-PROCESSORS The Controller gives general authorisation for the sub-processors listed at /legal/subprocessors. The Processor gives notice by email before adding or replacing a sub-processor that handles personal data, and the Controller may object on reasonable data protection grounds within fourteen days; if the objection cannot be resolved, the Controller may terminate the affected service without penalty. 8. ASSISTANCE Taking account of the nature of processing, the Processor assists the Controller with: (a) responding to data-subject requests; (b) security of processing; (c) personal data breach notification; (d) data protection impact assessments and prior consultation. 9. PERSONAL DATA BREACH The Processor notifies the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Controller's data, with the information described at /legal/incident-response. 10. DELETION OR RETURN On termination the Processor deletes or returns personal data at the Controller's choice, except where storage is required by law. Retention windows for operational data are published at /legal/data-retention. 11. AUDIT The Processor makes available the information necessary to demonstrate compliance with this Agreement and allows for and contributes to audits, on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, subject to confidentiality. 12. INTERNATIONAL TRANSFERS Where a sub-processor is located outside the EEA, the United Kingdom or Turkiye, transfers are made under that provider's standard contractual clauses or an equivalent lawful mechanism. 13. LIABILITY AND PRECEDENCE Liability under this Agreement is subject to the limitations in the Terms of Service. In case of conflict between this Agreement and the Terms of Service on the processing of personal data, this Agreement prevails. -------------------------------------------------------------------------------- SIGNATURES Processor: [LEGAL ENTITY NAME — TO BE SUPPLIED] Name ____________________ Title ____________________ Date ____________________ Signature ________________ Controller: Name ____________________ Title ____________________ Date ____________________ Signature ________________