Data Processing Addendum

Effective 15 September 2026. This Data Processing Addendum (the "DPA") forms part of the Terms of Service between ALIEN SOFTWARE LLC, a Wyoming limited liability company ("Clobber", "we") and the Customer ("you"), and applies where we process personal data on your behalf. Where this DPA and the Terms conflict on the subject of personal data, this DPA governs.

No signature is required. This DPA is incorporated into the Terms by reference and takes effect when you accept them. If your process requires a countersigned copy, write to [email protected].

#1. Definitions

"Data Protection Law" means every law applicable to a party's processing of Personal Data, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the GDPR as retained in United Kingdom law ("UK GDPR"), the Swiss Federal Act on Data Protection, and United States state privacy laws including the California Consumer Privacy Act as amended.

"Personal Data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data contained in Customer Data that we process on your behalf under the Terms.

"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

#2. Roles

2.1 For Customer Personal Data, you are the controller and we are the processor. Where you are yourself a processor for another controller, we are a subprocessor and this DPA applies as if references to controller were to that party.

2.2 For the Personal Data described in section 2 of our Privacy Policy that we determine the purposes of, such as account, billing, verification and website data, we are a controller, and that Privacy Policy rather than this DPA governs.

2.3 The boundary matters. Clobber is infrastructure, and you operate your own market and your own relationship with your end users. We have no direct relationship with your end users, we do not determine why or how their data is processed, and we do not require their identities in order to run the Service.

#3. Processing

3.1 Instructions. We process Customer Personal Data only on your documented instructions, which comprise the Terms, this DPA, and your configuration and use of the Service, including instructions given through the API. We will tell you if we believe an instruction breaches Data Protection Law, and may suspend that instruction until it is resolved.

3.2 Subject matter, duration, nature, purpose, categories and data subjects. As set out in Annex I.

3.3 Legal requirement. If law requires us to process beyond your instructions, we will tell you first unless that law prohibits it.

3.4 Your obligations. You warrant that you have a lawful basis for the Personal Data you send us, that you have given the notices and obtained any consents that Data Protection Law requires, and that your instructions comply with it. You will not send us special category data, and you will not send us the identity documents of your end users: the Service does not need them, and the Acceptable Use Policy does not permit their use for a purpose we would not expect.

#4. Confidentiality and personnel

We ensure that everyone authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality, receives access only on a need to know basis, and is trained in their obligations.

#5. Security

We implement and maintain the technical and organisational measures in Annex II, which implement Article 32 of the GDPR. We may update them as the Service evolves, provided the level of protection is not reduced.

Personal data breach. We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to us: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide everything at once, we will provide it in phases without undue further delay. We will assist you in meeting your own notification obligations, and we understand that the clock we are protecting is yours.

#6. Subprocessors

6.1 Authorisation. You give general written authorisation for us to engage subprocessors. The current list is at clobberhq.com/legal/subprocessors/.

6.2 Terms. We impose on every subprocessor data protection obligations at least as protective as those in this DPA, and we remain fully liable to you for their performance.

6.3 Changes and objection. We will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer Personal Data. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if we cannot within a reasonable time, you may terminate the affected environments and receive a refund of prepaid unused fees.

#7. Data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligations to respond to data subject requests under Chapter III of the GDPR. The Service gives you the ability to access, correct, export and delete data in your environments yourself, which is the primary way this assistance is delivered.

If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will tell them to contact you, and we will forward the request to you where we can identify the environment, unless legally prohibited.

#8. Assistance

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation with a supervisory authority.

#9. Deletion and return

On termination, and at your choice, we will delete or return Customer Personal Data. Deletion follows the schedule in the Terms and the Privacy Policy: your data remains available for export for 30 days after termination, the journal for your environment is retained for 12 months because it is the record by which the Service can be audited and restored, and backups expire on their own cycle. We will delete or de identify everything else within 90 days, except what we must keep by law or under a legal hold, which remains subject to this DPA for as long as we hold it.

#10. Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and contribute to audits conducted by you or an auditor you mandate. In the first instance this is satisfied by our security documentation, our completed security questionnaire, and written answers to your specific questions. Where Data Protection Law entitles you to more, we will agree the scope, timing and cost in advance, an audit may be conducted no more than once in any twelve months absent a breach or a supervisory authority requirement, and it may not extend to another customer's data or to anything that would compromise the security of the Service.

#11. International transfers

11.1 We are established in the United States. Where we process Customer Personal Data subject to the GDPR, the UK GDPR or Swiss law and transfer it out of the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated by reference and completed as follows:

11.2 United Kingdom. The International Data Transfer Addendum issued by the Information Commissioner (version B1.0) applies to UK transfers, with Tables 1 to 3 completed by reference to the above and Table 4 selecting neither party as entitled to end the addendum on a change to the approved addendum.

11.3 Switzerland. The SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner as the supervisory authority, and data subjects in Switzerland able to enforce their rights in Switzerland.

11.4 Additional measures. Encryption in transit and at rest, tenant isolation, least privilege internal access, and the government request handling described in section 6 of the Privacy Policy: we require valid legal process, produce only what it requires, challenge overbroad requests, and notify affected customers unless legally prohibited.

11.5 Remote access is a transfer, and here is where from. Customer Personal Data is stored in the region each environment is pinned to. Our personnel administer those systems remotely from the United States and from Argentina, under the controls in Annex II. We treat that access as a transfer and it is covered by the clauses above. We will update this section, and the Privacy Policy, before personnel in an additional country are given production access.

#12. United States state privacy law

Where the California Consumer Privacy Act applies, we act as a service provider. We do not sell or share Customer Personal Data, do not retain, use or disclose it for any purpose other than performing the Service, do not combine it with data from another source except as that Act permits, and will not act outside the direct business relationship with you. We certify that we understand and will comply with these restrictions. The equivalent terms apply where the privacy laws of other United States states apply.

#13. General

This DPA is governed by the law and jurisdiction stated in the Terms, except where Data Protection Law or the SCCs require otherwise, in which case those requirements prevail for the processing they govern. Each party's liability under this DPA is subject to the limitations in section 14 of the Terms, except where Data Protection Law does not permit that limitation.


#Annex I: description of the processing

Parties. Data exporter: the Customer, a controller (or a processor acting for its own controller), whose details are those on its Clobber account. Data importer: ALIEN SOFTWARE LLC, a Wyoming limited liability company, a processor providing hosted order book infrastructure.

Subject matter. Provision of the Service under the Terms.

Duration. For the term of the Terms, plus the retention periods in section 9.

Nature and purpose. Hosting, storing, transmitting and processing Customer Data so as to operate markets, match orders, maintain the ledger, deliver the market data feed, secure the Service, prevent abuse, meter usage and provide support.

Categories of data subjects. The Customer's end users, as identified by the Customer, and the Customer's own personnel who use the Service.

Categories of Personal Data. Account identifiers assigned by the Customer to its end users; any identifier, reference or metadata the Customer chooses to attach to an account, order or market; trading activity associated with those identifiers; and, for the Customer's own personnel, name, work email address, role and authentication and access data.

The Customer controls what is sent. The Service requires only an opaque account identifier per end user. Anything more identifying is present only because the Customer chose to send it, and section 3.4 restricts what may be sent.

Special category data. None. The Service is not designed for it and must not be used with it.

Frequency. Continuous, for the duration of the Terms.

Processing and storage locations. Storage and processing happen in the AWS region each environment is pinned to, chosen by the Customer. Administrative access is performed remotely by our personnel from the United States and from Argentina (section 11.5). Billing, email and operational telemetry subprocessors process in the locations listed at clobberhq.com/legal/subprocessors/.

Retention. As set out in section 9 and in the Privacy Policy.

Subprocessors. As listed at clobberhq.com/legal/subprocessors/, for the purposes and durations stated there.

Competent supervisory authority. Determined under clause 13 of the SCCs by reference to the data exporter's establishment or representative.

#Annex II: technical and organisational measures

The measures described at clobberhq.com/legal/security/, which forms part of this DPA and is summarised here as required by the SCCs:

Contact for all matters under this DPA: [email protected]