LEGAL · TEMPLATE

Data Processing Addendum

Template for early-access customers. It reflects how the Service actually works today and is pending review by counsel; the signed version prevails over this page.

1. Parties and roles

This Addendum forms part of the KYTGate Terms of Service between KYTGate ("Processor") and the customer identified in the order ("Controller"). The Controller determines why an address, transaction or customer reference is screened; the Processor screens it, records the decision and keeps the evidence on the Controller's instructions.

2. Subject matter, duration, nature and purpose

Processing of funding-related data to screen crypto transactions and wallet addresses against sanctions data, issuer freeze status, transaction integrity, processor verdicts and the Controller's own behaviour rules; to record decisions, cases and evidence; and to produce reports. Duration: the term of the Terms plus the retention period in section 8.

3. Categories of data and data subjects

Blockchain addresses and transaction identifiers; pseudonymous customer references chosen by the Controller; deposit, withdrawal and trading summary amounts and timestamps; optional device, IP and bank references supplied by the Controller with funding events; processor verdicts and evidence references; wallet ownership signatures; console user names and e-mail addresses; case notes written by the Controller's staff. Data subjects: the Controller's clients and the Controller's staff. The Processor does not receive identity documents, names of clients or KYC files unless the Controller writes them into case notes, which it should not.

4. Instructions

The Processor processes personal data only on documented instructions: the Terms, this Addendum, the Controller's API calls, console actions and tenant settings (mode, thresholds, retention). The Processor will inform the Controller if an instruction appears to infringe applicable law.

5. Confidentiality and personnel

Access to production data is limited to personnel who need it to operate the Service, bound by confidentiality, and every console access is recorded in an append-only audit log available to the Controller for its tenant.

6. Security measures

As described at /security, which forms part of this Addendum: encryption in transit and at rest, hashed credentials, role-based access, session limits, login throttling, tenant isolation verified by a recurring live audit, signed decision receipts, HMAC-signed webhooks, append-only audit logging, fail-closed decisioning and daily list refresh. The Processor may improve these measures but will not materially reduce them during the term.

7. Subprocessors

Vercel Inc. (hosting, USA/EEA), Neon Inc. (database, USA), Resend Inc. (transactional e-mail, USA), TRON DAO / TronGrid (Tron network reads), public blockchain RPC providers (network reads containing only the identifier checked). The Processor will give at least 30 days' notice of a new subprocessor by e-mail to the Controller's admin users; the Controller may object on reasonable data-protection grounds, and if the objection cannot be resolved may terminate the affected service without penalty.

8. Retention, deletion and return

Personal data is retained for the evidence period the Controller sets in its tenant settings (default seven years) or as long as a legal hold set by the Controller is active. On closure of the tenant the Processor disables access immediately and deletes all tenant data 30 days later, unless a legal hold is active. Before deletion the Controller may export all data it holds as a single JSON document from the console, including signed decision receipts that remain verifiable offline.

9. Assistance and data subject rights

The Processor will assist the Controller, by appropriate technical means (search, export, deletion within retention rules), in responding to data subject requests and in meeting its security, breach notification and impact assessment obligations, taking into account that the data is pseudonymous on the Processor's side.

10. Personal data breach

The Processor notifies the Controller without undue delay and no later than 48 hours after confirming a breach affecting the Controller's data, with the nature of the breach, categories and approximate volumes, likely consequences and measures taken.

11. Audits

The Controller may request, once per year or after a breach, the Processor's current security description, the latest isolation audit output and its tenant's audit log; and may conduct or mandate an audit on reasonable notice, at its own cost, limited to the Processor's processing of the Controller's data and subject to confidentiality.

12. International transfers

Where the GDPR or UK GDPR applies and data is transferred outside the EEA or UK, the parties rely on adequacy decisions or the Standard Contractual Clauses (module two, controller to processor), which are incorporated by reference and completed by the details in this Addendum.

13. Liability and precedence

Liability under this Addendum is subject to the limitations in the Terms. In case of conflict this Addendum prevails over the Terms for data-protection matters.

Template version 5 September 2026 · governing law and controller details to be completed in the signed order form.