This Data Processing Agreement (hereinafter "DPA") is part of, and governed by, the General Terms and Conditions of Service for BRADsearch. It governs the processing of personal data by UAB Invertus ("Processor") on behalf of its client ("Controller").

1. Definitions

Unless otherwise defined herein, capitalized terms shall have the meaning given under the GDPR.

2. Roles

Controller: The Client, as the data Controller, determines the purposes and means of the processing of personal data under this DPA. The Controller is responsible for ensuring that the processing of personal data complies with applicable data protection laws, including the GDPR.

Processor: UAB Invertus, acting as the data Processor, shall process personal data in accordance with this DPA, applicable data protection laws, and recognized industry best practices.

This DPA forms an integral part of the contractual relationship between the Parties and supplements the BRADsearch General Terms and Conditions of Service. It applies exclusively to the processing of personal data by the Processor on behalf of the Controller in the context of providing the BRADsearch services. This DPA becomes effective from the moment the Controller starts using the Services and the processing will continue for the duration of the subscription and until the Personal Data is deleted in accordance with this DPA.

3. Categories of Data Subjects

We may process personal data of various types of individuals in the course of our business. Depending on your relationship with us, we use your information for different purposes. The main categories of data subjects we handle, and the purposes for processing personal data in each case, are outlined below:

4. Types of Personal Data and Data Subjects

4.1 Data Provided by the Controller

The following categories of personal data may be submitted to the Processor by the Controller for processing under this Agreement:

4.2 Automatically Collected Data

When the Controller uses the BRADsearch Service, the following personal data may be collected and processed automatically:

This data is used exclusively for service delivery and support purposes and may be pseudonymized or aggregated to improve service reliability, performance and personalization.

4.3 Personal Data Processed as a Processor

As part of the BRADsearch Service, the Processor may process personal data submitted by the Controller that belongs to the Controller's own customers, merchants, users, or third-party contacts. This may include:

In these cases:

4.4 Categories of Data Subjects

The personal data processed under this Agreement may relate to the following categories of individuals:

5. Data Processing Purpose

The Processor shall process Personal Data only for the purposes described in this DPA and shall not process data beyond these purposes, except where required by law or explicitly authorized in writing by the Controller. This includes activities such as client support, security monitoring, and technical operations.

The Processor may process Personal Data only:

The Processor shall not use Personal Data for profiling, resale, or automated decision-making, unless explicitly instructed by the Controller in writing.

No processing shall take place beyond these purposes or outside the Controller's documented instructions.

The data processing purposes outlined herein are further supported by the publicly available BRADsearch Privacy Policy, which describes the Processor's general data handling practices in accordance with applicable law.

6. Data Protection and Party Obligations

6.1 General Obligations

Both Parties must ensure data is protected against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access - especially during electronic transmission. Each Party shall implement adequate technical and organizational measures in line with Article 32 of the GDPR.

6.2 Controller's Rights and Duties

6.3 Processor's Obligations

7. Data Processing Principle

Processing must follow the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality. Any further instructions regarding security or privacy become binding upon effect.

8. Disclaimer Of Liability

The Processor shall only be liable for damages directly resulting from its proven gross negligence or willful misconduct in performing obligations under this DPA.

The Controller remains solely and fully responsible for:

The Processor shall not be liable for any processing performed in accordance with the Controller's instructions.

The Controller shall indemnify and hold harmless the Processor against any third-party claims, regulatory actions, fines, or damages arising out of:

Where the Processor engages a Sub-processor, it shall ensure compliance with GDPR Article 28 requirements. The Processor shall only be liable for Sub-processors to the extent required by GDPR and shall not assume broader liability for their independent acts or omissions.

Limitation of Liability: Except for cases of gross negligence, willful misconduct, or mandatory liability under applicable law, the Processor's total cumulative liability under this Agreement shall in no event exceed the total fees paid by the Controller to the Processor for the Services in the twelve (12) months preceding the event giving rise to liability.

9. Confidentiality And Data Protection

Confidentiality: Each Party shall treat all personal data and other confidential information as strictly confidential and shall not disclose it to third parties without prior written consent, unless required by law.

Authorized Access: The Processor shall ensure only authorized personnel with a need-to-know basis have access to personal data, and that they are subject to confidentiality obligations.

Survival: The confidentiality obligations under this clause shall survive the termination of this DPA.

10. Sub-Processing

The Processor may engage Sub-processors to support the delivery and operation of the BRADsearch services, including for infrastructure, analytics, or related functionalities.

A list of current Sub-processors is maintained in Appendix A. The Controller hereby authorizes use of the listed Sub-processors.

The Processor shall notify the Controller in writing at least 15 calendar days before appointing any new or replacement Sub-processor. The Controller may object to a new Sub-processor only on reasonable, documented grounds relating to data protection. If such objection is not raised within the notice period, the new Sub-processor shall be deemed accepted. If an objection is raised, the Parties shall cooperate in good faith to find a suitable solution. If no agreement is reached, the Controller may terminate the affected service in writing, with thirty (30) days' notice.

The Processor shall enter into a written agreement with each Sub-processor that imposes obligations substantially equivalent to those in this DPA, especially ensuring compliance with Article 28 of the GDPR.

The Processor shall remain fully liable for the acts and omissions of its Sub-processors to the same extent it would be liable if performing the services directly.

Any international transfer of personal data by a Sub-processor outside the European Economic Area shall comply with applicable data protection laws, including appropriate safeguards such as Standard Contractual Clauses or adequacy decisions under Chapter V of the GDPR.

11. Security Measures

The Processor shall implement appropriate technical and organizational measures to protect personal data, as required under Article 32 of the GDPR. These include, where applicable:

The Processor shall ensure only authorized personnel have access to personal data and that they are bound by confidentiality obligations.

12. Personal Data Breaches

The Processor shall notify the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data.

The notification shall include, to the extent available:

Where complete information cannot be provided within 48 hours, the Processor shall provide the available details and supplement the notification as soon as further information becomes available.

The Processor shall cooperate fully with the Controller to support compliance with the Controller's obligations under Articles 33 and 34 of the GDPR, including assisting with communications to supervisory authorities and affected data subjects where required.

13. Return or Deletion of Data

Upon termination or expiry of the Services, the Processor shall, at the Controller's choice, either return or securely delete all personal data processed on behalf of the Controller, unless applicable law requires longer retention.

Unless otherwise agreed in writing, the Processor shall retain the data for up to one (1) year after termination for the sole purposes of potential reactivation, audit, or legal defense. After this period, all personal data shall be securely and irreversibly deleted.

If the Controller requests earlier deletion or data return, the Processor shall fulfill such request within thirty (30) days, provided no legal obligation prevents it.

Deletion shall be carried out using appropriate technical means, and confirmation shall be provided to the Controller upon written request.

14. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the Republic of Lithuania. Any disputes arising from or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Kaunas, Lithuania, unless otherwise agreed by the Parties in writing.

15. Miscellaneous

If any provision of this DPA is found to be invalid or unenforceable, the remainder shall remain valid and enforceable.

This DPA may only be amended by a written agreement signed or confirmed by both Parties.

This DPA becomes effective upon acceptance of the BRADsearch General Terms and Conditions of Service or upon mutual signature, as applicable.

No partnership, joint venture, or agency is created by this DPA.

16. Contact Information

For any questions or concerns regarding this Data Processing Agreement (DPA), please contact our support or:

Appendix A - Authorized Sub-Processors

Last updated: September 10, 2025

This Appendix forms an integral part of the Data Processing Agreement ("DPA") between the Controller and UAB Invertus ("Processor").

The following third-party service providers are authorized by the Controller to act as Sub-Processors, assisting the Processor in delivering the BRADsearch services. All Sub-Processors are bound by written agreements ensuring substantially similar data protection obligations as set out in the DPA and in compliance with Article 28 of the GDPR.