Data Processing Addendum

TEA Software Inc. · Effective: August 17, 2026 · Version 1.0

This Data Processing Addendum ("DPA") forms part of the agreement between TEA Software Inc. ("TEA") and the customer identified in that agreement ("Customer") governing Customer's use of TEA's platform and services (the "Customer Agreement"), and applies to the extent TEA processes Customer Personal Data on Customer's behalf in providing the services (the "Services"). If a countersigned copy is required by Customer's procurement process, contact legal@teasoftware.io.

1. Definitions

"Customer Personal Data" means personal data contained in Customer Data (as defined in the Customer Agreement) that TEA processes on Customer's behalf. "Data Protection Laws" means the laws applicable to the processing of Customer Personal Data, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and U.S. state privacy laws including the CCPA/CPRA. "SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914. "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by TEA. "Controller," "processor," "processing," and "data subject" have the meanings given in Data Protection Laws.

2. Roles and scope

Customer is the controller (or a processor acting for its own controllers) and TEA is a processor of Customer Personal Data. Annex I describes the subject matter, duration, nature, purpose, categories of data subjects, and types of personal data. Each party will comply with its own obligations under Data Protection Laws. Customer is responsible for the lawfulness of the Customer Personal Data it submits and for its instructions to TEA.

3. Processing instructions

TEA will process Customer Personal Data only on Customer's documented instructions, which consist of the Customer Agreement, this DPA, and Customer's configuration and use of the Services — unless processing is required by law, in which case TEA will notify Customer before processing (where legally permitted). TEA will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).

4. Confidentiality

TEA ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.

5. Security

TEA will implement and maintain the technical and organizational measures described in Annex II, designed to protect Customer Personal Data against Security Incidents. TEA may update those measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.

6. Sub-processors

Customer provides general authorization for TEA to engage sub-processors. TEA's current sub-processors are listed at teasoftware.io/sub-processors, and Customer may subscribe to change notifications by emailing legal@teasoftware.io. TEA will update that page at least 30 days before a new sub-processor processes Customer Personal Data (or as soon as reasonably practicable where a shorter period is necessary, such as for security reasons). Customer may object on reasonable, documented data-protection grounds within the notice period; the parties will discuss in good faith, and if no resolution is reached, Customer may terminate the affected Services in accordance with the Customer Agreement. TEA will impose data-protection obligations on sub-processors that are no less protective than those in this DPA and remains responsible for their performance.

7. Data subject requests

Taking into account the nature of the processing, TEA will assist Customer through appropriate technical and organizational measures in fulfilling Customer's obligation to respond to data subject requests. If TEA receives a request directly relating to Customer Personal Data, it will forward the request to Customer without undue delay and will not respond except to direct the data subject to Customer, unless legally required.

8. Assistance

Taking into account the nature of the processing and the information available to TEA, TEA will provide reasonable assistance to Customer with data protection impact assessments, consultations with supervisory authorities, and Customer's security and breach-notification obligations under Data Protection Laws.

9. Security Incidents

TEA will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident, and will provide information reasonably available to TEA about its nature, likely consequences, and the measures taken or proposed to address it, supplementing the notice as information becomes available. TEA will take reasonable steps to contain and remediate the Security Incident. Notification is not an acknowledgment of fault or liability.

10. Deletion and return

Upon termination or expiration of the Customer Agreement, TEA will, at Customer's choice, delete or return Customer Personal Data within 90 days, unless retention is required by law, in which case TEA will protect the retained data under this DPA and delete it when the requirement ends. Upon request, TEA will confirm deletion in writing. Public blockchains: Customer acknowledges that information recorded on public blockchain networks (such as wallet addresses and transaction data) is replicated across systems that TEA does not control and cannot be modified or deleted by TEA; deletion obligations under this DPA apply to Customer Personal Data stored in TEA-managed systems.

11. Audits and reports

TEA will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security policies and, when and as available, summaries of third-party audit reports or certifications. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by such documentation, Customer may conduct an audit no more than once per 12 months, on at least 30 days' notice, during business hours, subject to confidentiality obligations and without unreasonable disruption to TEA's operations.

12. International transfers

Where TEA processes Customer Personal Data protected by EEA, UK, or Swiss Data Protection Laws in a country not recognized as providing adequate protection, the parties agree that: (a) the SCCs (Module Two: controller-to-processor, and Module Three: processor-to-processor, as applicable) are incorporated into this DPA, completed with the details in Annex I and Annex II, with the optional docking clause included; (b) for UK transfers, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the ICO; and (c) for Swiss transfers, the SCCs apply with the adaptations required by the Swiss data protection authority. If there is a conflict between this DPA and the SCCs, the SCCs control.

13. CCPA / U.S. state privacy laws

To the extent Customer Personal Data is subject to the CCPA/CPRA or similar U.S. state laws, TEA acts as a "service provider" or "processor": TEA will not sell or share Customer Personal Data; will not retain, use, or disclose it for any purpose other than performing the Services or as permitted by law; will not combine it with personal information from other sources except as permitted for service providers; and certifies that it understands and will comply with these restrictions. TEA will notify Customer if it determines it can no longer meet its obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.

14. Liability

Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Customer Agreement, applied in the aggregate across the Customer Agreement and this DPA.

15. General

In case of conflict regarding the processing of Customer Personal Data, the order of precedence is: the SCCs, then this DPA, then the Customer Agreement. This DPA remains in effect for as long as TEA processes Customer Personal Data. This DPA is governed by the law governing the Customer Agreement, except where Data Protection Laws require otherwise.

Annex I — Details of processing

Data subjects: Customer's personnel and authorized users of the Services; representatives of Customer's own customers, partners, and counterparties, where Customer submits their data to the Services.

Categories of personal data: business contact details (name, email, role, organization); account credentials and access logs; usage, device, and log data; billing contacts and invoicing details; support communications; public wallet addresses and associated on-chain transaction data; miner, worker, and fleet identifiers and operational telemetry.

Special categories: none intended or required; Customer agrees not to submit special-category data to the Services.

Nature and purpose of processing: hosting, operating, securing, supporting, and improving the Services as described in the Customer Agreement, including mining pool operations, node services, wallet software, treasury workflows, reporting, and customer support.

Frequency and duration: continuous, for the term of the Customer Agreement plus the deletion period in Section 10.

Competent supervisory authority (SCCs): determined in accordance with Clause 13 of the SCCs based on Customer's establishment.

Annex II — Technical and organizational measures

  • Access control: role-based access with least privilege; multi-factor authentication for administrative and personnel access; periodic access reviews; access revocation within 24 hours of personnel offboarding.
  • Encryption: encryption of data in transit using TLS 1.2 or higher; encryption at rest for Customer Personal Data stored in TEA-managed environments.
  • Key management: wallet functionality built on multi-party computation (MPC); TEA does not hold customers' complete private keys; production credentials stored in managed secrets vaults with rotation policies.
  • Logging and monitoring: centralized logging of production systems, security monitoring and alerting, and audit trails for administrative actions.
  • Vulnerability management: periodic vulnerability assessments and third-party penetration testing, with remediation tracking.
  • Incident response: documented incident response runbook with severity levels, escalation paths, and post-incident review.
  • Change management: documented change control with review, approval, and rollback procedures for production changes.
  • Vendor management: security assessment of sub-processors and critical vendors proportionate to risk.
  • Availability and resilience: infrastructure hosted with Amazon Web Services; backups and recovery procedures; redundancy for critical services.
  • Personnel: confidentiality obligations, security awareness training, and background screening where permitted by law.
  • Physical security: provided through AWS data-center controls.

Annex III — Sub-processors

TEA's current sub-processors, the services they provide, and their locations are listed at teasoftware.io/sub-processors, which forms part of this DPA.

Contact

TEA Software Inc. · 300 Delaware Ave., Suite 210, Wilmington, DE 19801, USA · Mailing: 600 N Broad Street, Suite 5 #4138, Middletown, DE 19709, USA · +1 (302) 294-7070 · legal@teasoftware.io