VAULTN DATA PROCESSING AGREEMENT

V1.02 (Last updated: 2026-10-01; effective 2027-01-01 for existing Accounts)

RECITALS

(A) The Agreement between You and VaultN may require VaultN to process Personal Data on Your behalf.

(B) This Data Processing Agreement sets out the additional terms, requirements and conditions on which VaultN will process Personal Data when providing services under the Agreement. This Agreement contains the mandatory clauses required by Article 28(3) of the General Data Protection Regulation ((EU) 2016/679) (GDPR) for contracts between controllers and processors.


1. Definitions and Interpretation

1.1 Definitions

Applicable Law: all laws, regulations, and binding decisions of competent authorities applicable to a party or to the processing of Personal Data under this DPA.

Business Purposes: the services to be provided by VaultN to You as described in the Agreement.

Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: have the meanings given in the Data Protection Legislation.

Data Protection Legislation: all applicable data protection and privacy legislation in force from time to time in the European Union or any member state of the European Union, including but not limited to Regulation (EU) 2016/679 (GDPR) and its national implementing legislation in the Netherlands (Uitvoeringswet AVG).

EEA: the European Economic Area.

End User: a natural person who purchases or receives Digital Inventory from You or Your Connection through a retail transaction, whose personal data may be processed by VaultN solely as necessary to fulfil the relevant order.

Records: has the meaning given in Clause 12.

Standard Assistance: assistance provided by VaultN in fulfilling its obligations under this DPA at no additional cost to You, unless such assistance requires effort or resources beyond what is reasonably necessary for VaultN to meet its obligations under Article 28 GDPR, in which case VaultN may charge a reasonable fee agreed in advance.

Sub-Processor List: the list of approved subprocessors maintained by VaultN at https://vaultn.com/subprocessor-list/, as updated from time to time.

Term: this DPA’s term as defined in Clause 10.

1.2 This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA.

1.3 The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.

1.4 A reference to writing or written excludes fax but not email.

1.5 In the case of conflict or ambiguity between:

(a) any provision contained in the body of this DPA and any provision contained in the Annexes, the provision in the body of this DPA will prevail;

(b) the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Annexes, the provision contained in the Annexes will prevail; and

(c) any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail, save for any terms expressly agreed in writing between You and VaultN.

1.6 Where You and VaultN have entered into a separate executed data processing agreement as part of separately negotiated terms that covers the obligations set out in this DPA, that agreement supersedes this DPA in its entirety for the duration of those separately negotiated terms.

1.7 Where You are established in the United Kingdom or subject to the California Consumer Privacy Act, the applicable addendum set out in this DPA applies in addition to and supplements the terms of this DPA. In case of conflict between an addendum and the main body of this DPA, the addendum prevails for the jurisdiction it covers.

1.8 Where Services under the Agreement are provided by an affiliate of VaultN, including VaultN Marketplace B.V. under Section C (FastTrack) of the T&Cs, this DPA applies mutatis mutandis to the processing of Personal Data by that affiliate in connection with those Services, and references to VaultN are read as references to that affiliate for those Services, except where the affiliate determines the purposes and means of the processing in its own right, in which case this DPA does not apply to that processing and the parties act as independent controllers.


2. Personal Data Types and Processing Purposes

2.1 You and VaultN agree and acknowledge that for the purpose of the Data Protection Legislation:

(a) You are the Controller and VaultN is the Processor.

(b) You retain control of the Personal Data and remain responsible for Your compliance obligations under the Data Protection Legislation, including but not limited to, providing any required notices and obtaining any required consents, and for the written processing instructions You give to VaultN.

(c) ANNEX A describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which VaultN may process the Personal Data to fulfil the Business Purposes.


3. VaultN’s Obligations

3.1 VaultN will only process the Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with Your written instructions. VaultN will not process the Personal Data for any other purpose or in a way that does not comply with this DPA or the Data Protection Legislation. VaultN will promptly notify You if, in its opinion, Your instructions do not comply with the Data Protection Legislation.

3.2 VaultN will comply promptly with any written instructions from You requiring VaultN to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorised processing.

3.3 VaultN will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third parties unless You or this DPA specifically authorises the disclosure, or as required by Applicable Law, court or regulator. If Applicable Law, a court or regulator requires VaultN to process or disclose the Personal Data to a third party, VaultN will first inform You of such legal or regulatory requirement and give You an opportunity to object or challenge the requirement, unless Applicable Law prohibits the giving of such notice.

3.4 VaultN will reasonably assist You as Standard Assistance with meeting Your compliance obligations under the Data Protection Legislation, taking into account the nature of VaultN’s processing and the information available to VaultN, including in relation to Data Subject rights, data protection impact assessments under Article 35 GDPR and reporting to and consulting with the relevant regulator under the Data Protection Legislation under Article 36 GDPR.


4. VaultN’s Employees

4.1 VaultN will ensure that all of its employees, contractors, agents and any other persons authorised to access or process the Personal Data:

(a) are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations and use restrictions in respect of the Personal Data;

(b) have undertaken training on the Data Protection Legislation and how it relates to their handling of the Personal Data and how it applies to their particular duties; and

(c) are aware both of VaultN’s duties and their personal duties and obligations under the Data Protection Legislation and this DPA.


5. Security

5.1 VaultN will at all times implement appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data including, but not limited to, the security measures set out in ANNEX B.

5.2 VaultN will implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:

(a) the pseudonymisation and encryption of personal data;

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and

(d) a process for regularly testing, assessing and evaluating the effectiveness of the security measures.


6. Personal Data Breach

6.1 VaultN will without undue delay and in any event within 72 hours of becoming aware notify You in writing if it becomes aware of:

(a) the loss, unintended destruction or damage, corruption, or unusability of part or all of the Personal Data. VaultN will restore such Personal Data at its own expense as soon as possible.

(b) any accidental, unauthorised or unlawful processing of the Personal Data; or

(c) any Personal Data Breach.

6.2 Where VaultN becomes aware of (a), (b) and/or (c) above, it will, without undue delay, also provide You with the following written information:

(a) description of the nature of (a), (b) and/or (c), including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;

(b) the likely consequences; and

(c) a description of the measures taken or proposed to be taken to address (a), (b) and/or (c), including measures to mitigate its possible adverse effects; and

(d) the name and contact details of the designated contact from whom further information can be obtained.

6.3 Immediately following any accidental, unauthorised or unlawful Personal Data processing or Personal Data Breach, the parties will co-ordinate with each other to investigate the matter. Further, VaultN will reasonably co-operate with You in Your handling of the matter, including but not limited to:

(a) assisting with any investigation;

(b) providing You with physical access to any facilities and operations affected;

(c) facilitating interviews with VaultN’s employees, former employees and others involved in the matter including, but not limited to, its officers and directors;

(d) making available all relevant records, logs, files, data reporting and other materials required to comply with all Data Protection Legislation or as otherwise reasonably required by You; and

(e) taking reasonable and prompt steps to mitigate the effects and to minimise any damage resulting from the Personal Data Breach or accidental, unauthorised or unlawful Personal Data processing.

6.4 VaultN will not inform any third party of any accidental, unauthorised or unlawful processing of all or part of the Personal Data and/or a Personal Data Breach without first obtaining Your written consent, except when required to do so by Applicable Law. For the avoidance of doubt, this Clause applies to VaultN’s processing in its capacity as processor under this DPA and does not limit VaultN’s compliance with any mandatory regulatory reporting obligation applicable to VaultN directly under Applicable Law in a separate capacity.

6.5 VaultN agrees that You have the sole right to determine:

(a) whether to provide notice of the accidental, unauthorised or unlawful processing and/or the Personal Data Breach to any Data Subjects, the in-scope regulator, law enforcement agencies or others, as required by law or regulation or in Your discretion, including the contents and delivery method of the notice; and

(b) whether to offer any type of remedy to affected Data Subjects, including the nature and extent of such remedy.


7. Transfers of Personal Data

7.1 VaultN (and any subprocessor) will not transfer or otherwise process the Personal Data outside the EEA without obtaining Your prior written consent, except where such transfer is made to subprocessors listed in the Sub-Processor List, in which case Your acceptance of this DPA constitutes prior written consent for those transfers, which shall be made on the basis of Standard Contractual Clauses as adopted by the European Commission (EU Commission Decision 2021/914) or such other transfer mechanism as is valid under Chapter V GDPR, a copy of which VaultN will provide to You upon request.


8. Subprocessors

8.1 Other than those subprocessors listed in the Sub-Processor List, VaultN will not authorise any other third party or subprocessor to process the Personal Data. VaultN will notify You of any intended addition to or replacement of a subprocessor at least 30 days in advance via the Platform or by email. You may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith, and failing resolution You may terminate the affected Services.

8.2 Where the subprocessor fails to fulfil its obligations under the written agreement with VaultN which contains terms substantially the same as those set out in this DPA, VaultN remains fully liable to You for the subprocessor’s performance of its agreement obligations.

8.3 You and VaultN agree that VaultN will be deemed by them to control legally any Personal Data controlled practically by or in the possession of its subprocessors.


9. Complaints, Data Subject Requests and Third-Party Rights

9.1 VaultN will take such technical and organisational measures as may be appropriate, and promptly provide such information to You as You may reasonably require, to enable You to comply with:

(a) the rights of Data Subjects under the Data Protection Legislation, including, but not limited to, subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and

(b) information or assessment notices served on You by the relevant regulator under the Data Protection Legislation.

9.2 VaultN will notify You immediately in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party’s compliance with the Data Protection Legislation.

9.3 VaultN will notify You without undue delay and in any event within 15 calendar days if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Data Protection Legislation.

9.4 VaultN will give You as Standard Assistance its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.

9.5 VaultN will not disclose the Personal Data to any Data Subject or to a third party other than in accordance with Your written instructions, or as required by Applicable Law.


10. Term and Termination

10.1 This DPA will remain in full force and effect so long as:

(a) the Agreement remains in effect; or

(b) VaultN retains any of the Personal Data related to the Agreement in its possession or control (the “Term”).

10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect the Personal Data will remain in full force and effect.

10.3 If a change in any Data Protection Legislation prevents either party from fulfilling all or part of its obligations under the Agreement, the parties may agree to suspend the processing of the Personal Data until that processing complies with the new requirements. If the parties are unable to bring the Personal Data processing into compliance with the Data Protection Legislation within the period applicable to material changes under the Agreement, which the parties agree constitutes a material change for the purposes of the Agreement, and under no circumstances less than 30 days, either party may terminate the Agreement in accordance with the notice provisions of the Agreement.


11. Data Return and Destruction

11.1 At Your request, VaultN will give You, or a third party nominated in writing by You, a copy of or access to all or part of the Personal Data in its possession or control in the format and on the media reasonably specified by You.

11.2 On termination of the Agreement for any reason or expiry of its term, VaultN will securely delete or destroy or, if directed in writing by You, return and not retain, all or any of the Personal Data related to this DPA in its possession or control, except for one copy that it is required to retain for internal auditing purposes only, for no longer than 3 years following the date of deletion or return, unless a longer retention period is required under Applicable Law.

11.3 If any law, regulation, or government or regulatory body requires VaultN to retain any documents, materials or Personal Data that VaultN would otherwise be required to return or destroy, it will notify You in writing of that retention requirement, giving details of the documents, materials or Personal Data that it must retain, the legal basis for such retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.


12. Records

12.1 VaultN will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, subprocessors as listed in the Sub-Processor List, the processing purposes, categories of processing, and a general description of the technical and organisational security measures referred to in Clause 5.1 (the “Records”).

12.2 VaultN will ensure that the Records are sufficient to enable You to verify VaultN’s compliance with its obligations under this DPA and the Data Protection Legislation and VaultN will provide You with copies of the Records upon request.


13. Audit

13.1 VaultN will, upon Your reasonable written request and no more than once per calendar year (unless a Personal Data Breach has occurred), make available to You the following in order of preference:

(a) a current ISO 27001 certification and associated Statement of Applicability, which VaultN may provide in satisfaction of its audit obligations under this Clause;

(b) where You reasonably consider that (a) does not demonstrate sufficient compliance, relevant records and documentation as necessary to verify VaultN’s compliance with this DPA, with no on-site access required; and

(c) where a Personal Data Breach has occurred or a supervisory authority requires it, or where You have reasonable grounds to believe that the information provided under (a) or (b) does not adequately demonstrate compliance with Article 28 GDPR, provided that You have first exhausted the remedies under (a) and (b) and provided VaultN with written reasons for Your belief, an on-site audit, the scope, timing and cost of which shall be agreed in advance between You and VaultN, and for which VaultN may require the appointment of a mutually agreed independent third-party auditor under a non-disclosure agreement.

13.2 In all cases, You will provide VaultN with reasonable prior written notice of no less than 30 calendar days.


14. Warranties

14.1 VaultN warrants and represents that:

(a) its employees, agents and any other person or persons accessing the Personal Data on its behalf are reliable and trustworthy and have received the required training on the Data Protection Legislation;

(b) it and anyone operating on its behalf will process the Personal Data in compliance with the Data Protection Legislation and other laws, enactments, regulations, orders, standards and other similar instruments;

(c) it has no reason to believe that the Data Protection Legislation prevents it from providing any of the Agreement’s contracted services; and

(d) considering the current technology environment and implementation costs, it will take appropriate technical and organisational measures to prevent the accidental, unauthorised or unlawful processing of Personal Data and the loss or damage to the Personal Data, and ensure a level of security appropriate to:

(i) the harm that might result from such accidental, unauthorised or unlawful processing and loss or damage;

(ii) the nature of the Personal Data protected; and

(iii) comply with all applicable Data Protection Legislation and its information and security policies, including the security measures required in Clause 5.1.

14.2 You warrant and represent that VaultN’s expected use of the Personal Data for the Business Purposes and as specifically instructed by You will comply with the Data Protection Legislation.


15. Indemnification

15.1 VaultN agrees to indemnify, keep indemnified and defend at its own expense You against all costs, claims, damages or expenses incurred by You or for which You may become liable due to any failure by VaultN or its employees, subcontractors or agents to comply with any of its obligations under this DPA and/or the Data Protection Legislation. Similarly, You agree to indemnify, keep indemnified and defend at Your own expense VaultN against all costs, claims, damages or expenses incurred by VaultN or for which VaultN may become liable due to any failure by You or Your employees, subcontractors or agents to comply with any of Your obligations under this DPA and/or the Data Protection Legislation (including Your unlawful instructions).

15.2 Notwithstanding Clause 12 (Liability) of Section A (General Terms) of the T&Cs, VaultN’s liability under this DPA, including the indemnity in Clause 15.1, is subject to the limitations and exclusions of liability in the T&Cs, which apply to this DPA as if set out in full, except to the extent that such liability cannot be limited or excluded under Applicable Law.


16. Notices

16.1 Any notice given under or in connection with this DPA shall be given in accordance with the notice provisions of the Agreement. Notices from You to VaultN shall be sent to [email protected] or such other address as VaultN notifies You in writing from time to time.


17. Governing Law

17.1 This DPA is governed by the laws of the Netherlands. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands, consistent with the governing law and jurisdiction provisions of the Agreement.


UK GDPR ADDENDUM TO THE VAULTN DATA PROCESSING AGREEMENT

This Addendum forms part of the DPA and applies where You are established in the United Kingdom or where You process personal data subject to the UK GDPR in connection with the Services. To the extent of any conflict between this Addendum and the main body of the DPA, this Addendum prevails for UK GDPR processing only.


1. Definitions

UK GDPR has the meaning given in section 3(10) of the Data Protection Act 2018, as supplemented by section 205(4) of that Act.


2. Modifications to the DPA

To the extent that VaultN processes personal data subject to the UK GDPR on Your behalf, the DPA applies with the following modifications:

(a) References to Data Protection Legislation include the UK GDPR and the Data Protection Act 2018.

(b) References to Standard Contractual Clauses mean the International Data Transfer Agreement (IDTA) issued by the UK Information Commissioner’s Office, or the UK Addendum to the EU SCCs as applicable and approved by the UK Secretary of State, or such other valid transfer mechanism.

(c) References to supervisory authority include the UK Information Commissioner’s Office.

(d) The governing law of this Addendum, to the extent it covers UK GDPR processing only, is the law of England and Wales. For the avoidance of doubt, all other provisions of the DPA and the Agreement remain governed by Dutch law.


3. Liability

VaultN’s liability for breaches of this Addendum is subject to the same limitations as set out in Clause 15 of the DPA. Nothing in this Addendum creates liability beyond those limits.


4. Your Warranty

You warrant that You have the legal basis required under the UK GDPR for sharing personal data with VaultN under this Addendum.


CCPA ADDENDUM TO THE VAULTN DATA PROCESSING AGREEMENT

This Addendum forms part of the DPA and applies where You are a business subject to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act 2020 (together, CCPA) and You share personal information with VaultN in connection with the Services. To the extent of any conflict between this Addendum and the main body of the DPA, this Addendum prevails for CCPA processing only.


1. Role of VaultN

The parties acknowledge that to the extent VaultN processes personal information as defined under CCPA on Your behalf, VaultN acts as a Service Provider as defined under CCPA Section 1798.140(ag).


2. VaultN’s Obligations

VaultN confirms that it:

(a) will not sell or share personal information received from You;

(b) will not retain, use, or disclose personal information for any purpose other than performing the Services specified in the Agreement;

(c) will not retain, use, or disclose personal information outside the direct business relationship between VaultN and You; and

(d) will notify You if VaultN determines it can no longer meet its obligations under CCPA.


3. Your Warranty

You represent and warrant that You have provided all notices and obtained all consents required under CCPA for sharing personal information with VaultN as a Service Provider.


4. Scope of Processing

VaultN’s obligations under this Addendum are strictly limited to the personal information processed in the course of providing the Services. VaultN does not process consumer personal information as defined under CCPA except as strictly necessary for order fulfilment. VaultN does not process sensitive personal information as defined under CCPA Section 1798.140(ae).


5. Liability

VaultN’s liability for any breach of this Addendum is subject to the limitations set out in Clause 15 of the DPA. Nothing in this Addendum creates liability beyond those limits.


6. Governing Law

This Addendum does not modify VaultN’s governing law position. The Agreement and DPA remain governed by Dutch law. This Addendum supplements the DPA solely to address CCPA compliance obligations and does not constitute a submission to California jurisdiction.


ANNEX A: Personal Data Processing Details

Subject matter of processing

VaultN processes Personal Data as necessary to provide the Services under the Agreement, including the operation and maintenance of the VaultN Platform and all Services and Add-Ons provided thereunder.

Duration of processing

As set out in Clause 10 of this DPA.

Nature of processing

Collection, storage, retrieval, transmission, and deletion of Personal Data as necessary to provide the Services under the Agreement.

Business Purposes

As defined in the Agreement and in the applicable Sections and Clauses of the T&Cs.

Personal Data Categories

The following categories of Personal Data may be processed by VaultN in the course of providing the Services:

  • Account and User data: names, email addresses, and job titles of Users, and individuals at Your Connections who are given access to the Platform in connection with Your Account.
  • IP addresses: collected at the point of API authentication and order creation for security, fraud prevention, and regional access control purposes.
  • Unique end-user identifiers: pseudonymised identifiers passed by You or Your Connections to identify End Users in the context of order fulfilment, provided in hashed form.
  • Unique order identifiers: internal and third-party order reference identifiers (including clientOrderReference and orderGuid) generated or passed in the course of order creation, reservation, completion, and fulfilment.
  • Platform authentication credentials: where direct entitlement processing is enabled, authentication tokens or credentials passed by You or Your Connections to facilitate fulfilment of digital assets directly to an End User’s platform account.

You warrant that You have obtained all necessary consents and have the required legal basis under Applicable Law for sharing the Personal Data referred to in categories 2 to 5 above with VaultN, as required under the Agreement.

Data Subject Types

Users as defined in the Agreement, and End Users to the extent their Personal Data is processed in categories 2 to 5 above.


ANNEX B: Security Measures

VaultN’s technical and organisational security measures are governed by VaultN’s Information Security Policy, as published and amended from time to time by VaultN and available upon request at [email protected] (the “ISP”). The ISP is the sole source of truth for VaultN’s security measures and takes precedence over the overview below in the event of conflict.

The following is a high-level overview of VaultN’s current security measures as reflected in the ISP:

Access control: Access to Personal Data is restricted to authorised personnel on a need-to-know basis. Role-based access controls are implemented and reviewed periodically. Multi-factor authentication is required for access to production systems.

Encryption: Personal Data is encrypted in transit using TLS 1.2 or higher. Personal Data at rest is encrypted using industry-standard encryption protocols.

Incident response: VaultN maintains a documented information security incident response procedure. Security incidents are logged, investigated, and escalated in accordance with the ISP and the breach notification obligations in Clause 6 of this DPA.

Business continuity and availability: VaultN maintains backup and recovery procedures to ensure the availability and resilience of processing systems. Recovery procedures are tested periodically in accordance with the ISP.

Vendor and subprocessor security: Third-party subprocessors are assessed for security compliance prior to engagement and are contractually required to maintain security standards consistent with the ISP. The current list of approved subprocessors is maintained at the Sub-Processor List.

Staff training and awareness: All personnel with access to Personal Data receive training on data protection and information security obligations on an ongoing basis.

Physical security: Access to VaultN’s physical infrastructure is restricted and controlled. VaultN’s cloud infrastructure is hosted on Microsoft Azure, which maintains its own physical security certifications and controls.

VaultN reviews and updates the ISP at least annually. Where an update to the ISP materially reduces the level of security provided to You, VaultN will notify You in accordance with Clause 16 of this DPA.


Previous versions

Accounts registered before 1 October 2026 remain subject to the previous stack until 31 December 2026. Those documents stay available here for review: