Legal

Data Processing Addendum

Supplements the Partner Platform Terms in respect of personal-data processing under EU GDPR, UK GDPR, and the Hong Kong Personal Data (Privacy) Ordinance.

Last revised: 25 May 2026

Defined terms not defined here have the meaning given in the NAS Partner Platform Terms (the “Platform Terms”).

This Data Processing Addendum (the “DPA”) supplements and forms part of the Platform Terms entered into between Nano Advanced Services Limited (“NAS”) and the Partner (“Partner”) (together, the “Parties”). This DPA applies to NAS’s processing of personal data on behalf of Partner in connection with the Services.

In the event of conflict between this DPA and the Platform Terms in respect of personal-data processing, this DPA prevails.


1. Definitions

In this DPA, the following terms have the meanings set out below. Other capitalised terms have the meanings given in the Platform Terms.


2. Roles and Scope

2.1 Customer Personal Data. In respect of Customer Personal Data: - Partner is the Controller for Processing carried out in connection with its Program; - NAS is a Processor acting on Partner’s documented instructions; - NAS’s regulated Back-end Partners (as defined in Section 4.1 of the Platform Terms) are themselves Controllers in respect of the Personal Data they Process for their own regulated purposes (including statutory record-keeping, regulatory reporting, sanctions screening, and fraud and AML obligations under the licences and authorisations they hold).

2.2 Operator Personal Data. In respect of Operator Personal Data, NAS acts as an independent Controller (for example, when administering the Partner Account, billing, support, security, and platform analytics). NAS’s processing of Operator Personal Data is governed by NAS’s privacy notice.

2.3 Instructions. Partner’s instructions to NAS in respect of Customer Personal Data are set out in this DPA, in the Platform Terms (including the Schedules and any Program Order), and in NAS’s published documentation. Partner may give additional instructions in writing; NAS will inform Partner if NAS reasonably believes that an instruction would result in a breach of Applicable Data Protection Law and may, on that basis, refuse to act on the instruction.

2.4 Subject matter and duration. The subject matter and duration of the Processing are described in Annex A (Processing Particulars) to this DPA.


3. NAS Obligations as Processor

NAS shall, in respect of Customer Personal Data:

3.1 Process only on instructions. Process Customer Personal Data only on Partner’s documented instructions, except where required by Applicable Law (in which case NAS will inform Partner of that legal requirement before Processing unless the law prohibits such information).

3.2 Confidentiality. Ensure that persons authorised to Process Customer Personal Data are under appropriate confidentiality obligations (whether contractual or statutory).

3.3 Security. Implement the technical and organisational measures described in Annex B (Security Measures) to ensure a level of security appropriate to the risk to the rights and freedoms of Data Subjects.

3.4 Sub-processors. Engage Sub-processors only in accordance with Section 6.

3.5 Data Subject rights assistance. Assist Partner, by appropriate technical and organisational measures, in fulfilling Partner’s obligation to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law (rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). NAS will forward to Partner without undue delay any Data Subject request received directly by NAS that concerns Customer Personal Data.

3.6 Assistance with compliance obligations. Assist Partner in complying with its obligations under Articles 32 to 36 of the EU GDPR (or equivalent provisions of the UK GDPR or HK PDPO), taking into account the nature of the Processing and the information available to NAS — including obligations relating to security, breach notification, data-protection impact assessments, and consultation with Supervisory Authorities.

3.7 Return or deletion on termination. On termination or expiry of the Platform Terms, return to Partner or delete (at Partner’s choice) all Customer Personal Data, unless retention is required by Applicable Law (in which case NAS will inform Partner of the legal basis for retention and the retention period). Where Personal Data is held by NAS’s regulated Back-end Partners for their own regulated purposes, NAS’s deletion or return obligation is limited to the data held by NAS itself.

3.8 Audit and information. Make available to Partner the information necessary to demonstrate compliance with this DPA and Article 28 of the EU GDPR (or equivalent), and allow for and contribute to audits, including inspections, in accordance with Section 7.

3.9 Personal Data Breach notification. Notify Partner without undue delay (and in any event within forty-eight (48) hours) of becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide Partner with the information reasonably required to assist Partner in meeting its breach-notification obligations to Supervisory Authorities and Data Subjects.


4. Partner Obligations as Controller

Partner shall:

4.1 Lawful basis. Ensure that there is a lawful basis under Applicable Data Protection Law for all Processing of Customer Personal Data by Partner and by NAS on Partner’s instructions, including for any disclosure to NAS and any further Processing by NAS in connection with the Services.

4.2 Notices and consents. Provide all required privacy notices to Data Subjects, and obtain all required consents (including any consent required for cross-border transfers, marketing, or Processing of Special Category Data), in respect of Customer Personal Data Processed in connection with the Services.

4.3 Data minimisation. Submit to NAS only the Personal Data needed for the Services, and avoid submitting Special Category Data except where strictly necessary for an identified Service (such as identity verification).

4.4 Compliance with instructions of regulated parties. Comply with the data-protection requirements imposed by NAS’s regulated Back-end Partners (including the regulated card-issuer and the regulated custodian) and the applicable payment network, where these go beyond those in this DPA.


5. Operator Personal Data

NAS Processes Operator Personal Data as a Controller for the following purposes: - Administering the Partner Account (account creation, authentication, access management); - Providing customer service and support; - Billing and managing the commercial relationship; - Platform security, fraud detection, and abuse prevention; - Service-improvement analytics (in aggregate or pseudonymised form where reasonably practicable); - Complying with NAS’s own legal, regulatory, and tax obligations.

The lawful bases relied on are the performance of the Platform Terms (a contract to which the Operator Personal Data subject is connected as principal or representative), NAS’s legitimate interests in operating, securing, and improving the platform, and compliance with legal obligations. Further detail is in NAS’s privacy notice.


6. Sub-processors

6.1 General authorisation. Partner authorises NAS to engage Sub-processors to Process Customer Personal Data, subject to the requirements of this Section 6.

6.2 Sub-processor Schedule. The Sub-processors currently engaged are listed in the Sub-processor Schedule, which is shared with Partner under non-disclosure agreement during on-boarding and on Partner’s reasonable request thereafter.

6.3 New Sub-processors. NAS will give Partner at least thirty (30) calendar days’ prior written notice of the addition or replacement of any Sub-processor that will Process Customer Personal Data. Partner may, within fifteen (15) calendar days of receiving such notice, object on reasonable data-protection grounds. The Parties shall discuss in good faith to address the objection. If the Parties cannot reach agreement, either Party may terminate the affected Service or the Platform Terms in accordance with Section 17 of the Platform Terms, without penalty.

6.4 Sub-processor obligations. NAS shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those imposed on NAS by this DPA, including the obligations required by Article 28(3) of the EU GDPR (and equivalent provisions of the UK GDPR and HK PDPO).

6.5 Liability for Sub-processors. NAS remains responsible to Partner for the acts and omissions of its Sub-processors in respect of Customer Personal Data, as if such acts or omissions were NAS’s own.


7. Audit Rights

7.1 Information. On Partner’s written request (and not more than once in any twelve-month period, unless required by Applicable Data Protection Law or by a Supervisory Authority), NAS shall make available to Partner the information necessary to demonstrate compliance with this DPA. This includes, where available, the most recent third-party audit reports (such as SOC 2 Type II), penetration-test summary letters, and certifications.

7.2 Inspections. Where the information provided under Section 7.1 is not sufficient to demonstrate compliance, Partner may, on reasonable prior notice (and not less than thirty (30) calendar days, except where required by a Supervisory Authority), conduct an audit of NAS’s processing of Customer Personal Data. Audits shall be conducted during normal business hours, by Partner’s personnel or by an independent auditor reasonably acceptable to NAS, and shall be subject to appropriate confidentiality obligations. The auditor shall not have access to other NAS customers’ data, to NAS’s source code, or to NAS’s trade secrets, except to the extent strictly necessary to verify compliance.

7.3 Costs. Each Party bears its own audit costs, except where the audit identifies a material breach of this DPA by NAS, in which case NAS shall bear Partner’s reasonable audit costs.

7.4 Regulatory audits. Nothing in this Section 7 limits any audit, inspection, or information-gathering right of a Supervisory Authority.


8. International Data Transfers

8.1 Hosting. Customer Personal Data captured through the Partner-hosted Surfaces resides on Partner’s own hosting infrastructure (Partner is the host as well as the controller). The data NAS Processes through the central orchestration API on Partner’s behalf is hosted on cloud infrastructure operated by a tier-one cloud-services provider in the European Union (primary location: Frankfurt, Germany). NAS may engage Sub-processors located outside the EU/EEA, the UK, and Hong Kong to support specific Services; the location of each Sub-processor is disclosed in the Sub-processor Schedule.

8.2 EU and UK transfers. Where a Restricted Transfer of Customer Personal Data occurs from the EU/EEA, the United Kingdom, or another jurisdiction recognising the SCCs, the transfer is governed by: - For transfers from the EU/EEA: the EU SCCs (Implementing Decision (EU) 2021/914), with the following selections — Module 2 (Controller to Processor) where Partner is the Controller and NAS is the Processor; Module 3 (Processor to Sub-processor) where Partner is itself a Processor; Clause 7 (docking clause) included; Clause 9 option 2 (general authorisation of Sub-processors with 30-day notice) selected; Clause 11 (optional independent dispute body) not selected; Clause 17 (governing law) — the law of the EU member state in which the data exporter is established; Clause 18 (forum) — the courts of that member state. The annexes to the SCCs are populated by reference to Annex A (Processing Particulars) and Annex B (Security Measures) of this DPA and to the Sub-processor Schedule. - For transfers from the United Kingdom: the UK International Data Transfer Agreement (the “IDTA”) or the UK Addendum to the EU SCCs, at the data exporter’s election, as the same may be amended from time to time.

8.3 Hong Kong transfers. Where Customer Personal Data is transferred from Hong Kong to a jurisdiction outside Hong Kong, the Parties will rely on the consent of the Data Subject (where obtained by Partner under Section 4.2), on contractual safeguards (including the obligations in this DPA), and on the Recommended Model Contractual Clauses published by the Hong Kong Privacy Commissioner for Personal Data, as applicable.

8.4 Onward transfers. NAS shall not transfer Customer Personal Data outside the EU/EEA, the UK, or Hong Kong (as applicable) other than to a Sub-processor that has agreed to equivalent data-protection obligations and through an appropriate transfer mechanism.


9. Liability

9.1 Limitation. Each Party’s liability under this DPA is subject to the limitation-of-liability provisions of the Platform Terms (Section 16), without prejudice to either Party’s responsibilities to Data Subjects under Applicable Data Protection Law.

9.2 Data Subject claims. Where a Data Subject makes a claim against either Party arising from Processing of Customer Personal Data, the Parties shall cooperate in good faith on the response, and each Party shall be responsible for the part of any damage attributable to its breach of its obligations under this DPA or under Applicable Data Protection Law.


10. Term and Termination

10.1 Term. This DPA takes effect on the Effective Date of the Platform Terms and continues for the duration of the Platform Terms, plus any wind-down period and any period thereafter during which NAS retains Customer Personal Data in accordance with Section 3.7.

10.2 Effect of termination. On termination of the Platform Terms, the obligations in this DPA in respect of Customer Personal Data continue to apply for so long as NAS Processes Customer Personal Data.


Annex A — Processing Particulars

A.1 Subject matter and duration of Processing. The subject matter of the Processing is the provision of the Services described in the Platform Terms. The duration is the term of the Platform Terms plus any wind-down period and any retention period required by Applicable Law.

A.2 Nature and purpose of Processing. The Processing is performed for the purpose of providing the Services, including: Customer onboarding, identity verification, account servicing, transaction processing, wallet and ledger maintenance, card issuance and lifecycle management, transactional messaging, fraud and abuse prevention, security monitoring, audit-log capture, regulatory reporting on behalf of Partner and NAS’s regulated Back-end Partners, and customer-support tooling.

A.3 Categories of Data Subjects. - Partner’s Customers (individuals and authorised representatives of business Customers); - Authorised personnel of business Customers (where the Customer is an organisation); - Persons identified in identity-verification documents (e.g., persons referenced on a Customer’s company register); - Sender, recipient, and counter-party identifiers in transaction data.

A.4 Categories of Customer Personal Data. - Identity data: full name, date of birth, nationality, country of residence, government-issued identification document details (including type, number, issuing authority, expiry), photograph, signature, biometric facial-recognition data where used for identity verification. - Contact data: postal address, email address, telephone number. - Authentication data: hashed passwords, OTP records, device identifiers, IP address, login history. - Financial data: account balances, card details (tokenised — the Personal Account Number and CVV do not reside on NAS systems), transaction records, on/off-ramp records. - Business data (for business Customers): company name and registration number, beneficial-ownership records, directors and officers, business address. - Communications data: customer-support messages, notification records. - Audit data: timestamps, IP addresses, user-agent strings, and other technical metadata relating to Customer activity.

A.5 Special Category Data. Biometric data (facial-recognition data) is Processed where used for identity verification, on the legal basis selected by Partner and disclosed to Data Subjects (typically Customer consent or substantial-public-interest grounds).

A.6 Frequency. Continuous, for the duration of the Platform Terms.

A.7 Recipients. The Sub-processors listed in the Sub-processor Schedule; NAS’s regulated Back-end Partners (including the regulated card-issuer and the regulated custodian appointed by NAS); and, where required by Applicable Law or by lawful Regulatory Authority direction, Regulatory Authorities.


Annex B — Security Measures

NAS implements technical and organisational measures appropriate to the risk to the rights and freedoms of Data Subjects, including the following.

B.1 Access control. - Identity-and-access-management with role-based access control; - Multi-factor authentication for all administrative access; - Least-privilege principle for production-system access; - Periodic access reviews; immediate revocation on personnel change.

B.2 Network and transport security. - All Backend API and webhook traffic encrypted in transit using TLS 1.2 or higher; - Network segmentation and firewalling between application, data, and management tiers; - Web application firewalling and rate-limiting at the edge.

B.3 Application security. - Secure software development lifecycle, including peer code review and dependency-vulnerability scanning; - Regular penetration testing by qualified third parties; - Secrets stored in a managed secrets-management service, not in code or configuration files; - Audit logging of administrative actions and Customer-impacting events; - Webhook payload signing using HMAC-SHA256 with constant-time signature verification.

B.4 Data-at-rest protection. - Customer Personal Data at rest is encrypted, including database encryption and object-storage encryption, with keys managed by a managed key-management service; - Card PAN and CVV are not stored on NAS systems (PCI scope is bounded by tokenisation at the regulated card-issuer).

B.5 Backup and resilience. - Production data backed up regularly to the fallback geographic location; - Restoration procedures tested periodically; - Business-continuity and disaster-recovery plans maintained and tested.

B.6 Personnel. - Background checks on personnel with production-system access (to the extent permitted by law); - Security training on hire and at least annually thereafter; - Confidentiality obligations imposed by employment or contractor agreement.

B.7 Sub-processor management. - Due-diligence assessment of Sub-processors prior to engagement; - Contractual data-protection obligations imposed by written agreement; - Periodic re-assessment.

B.8 Incident response. - Documented incident-response plan; - 24/7 on-call coverage for production incidents; - Personal-data-breach notification to Partner within forty-eight (48) hours of becoming aware (see DPA Section 3.9).

B.9 Physical security. - Production infrastructure operated within tier-one cloud-provider data centres benefiting from physical-security controls including biometric access, 24/7 monitoring, and certified compliance frameworks (including ISO 27001 and SOC 2). - NAS office premises subject to access control appropriate to the data handled there.

B.10 Ongoing improvement. - Periodic review of these measures and adjustment in line with the evolving threat landscape, technical capabilities, and regulatory expectations.