Relixr Ltd — Data Processing Agreement (Standard Form) Last updated: 1 August 2026 This standard DPA covers Relixr's processing of Customer Personal Data as a processor when providing the Relixr Services. 1. Roles. Customer is Controller of Customer Personal Data in prompts, completions, and other customer content submitted via the API. Relixr is Processor for that content. For Relixr account, billing, and Relixr's own security/abuse data, Relixr acts as an independent controller as described in the Privacy Policy. 2. Instructions. Relixr processes Customer Personal Data only to provide the Services per Customer configuration and Relixr's published practices, unless required otherwise by law. 3. Security. Relixr applies appropriate technical and organizational measures, including encryption in transit, access controls, and hashed API credentials. Overview: https://relixr.com/trust and https://relixr.com/security 4. Subprocessors. Current list available on request via https://relixr.com/trust/request. Material changes notified by email where required. 5. International transfers. Where required, Relixr uses appropriate safeguards such as Standard Contractual Clauses (and UK transfer addenda where applicable). 6. Assistance and incidents. Relixr will reasonably assist with data-subject requests and will notify Customer without undue delay of personal-data breaches affecting Customer Personal Data under this DPA. 7. Deletion. Upon termination or written request, Relixr will delete or return Customer Personal Data subject to Customer's logging settings, except data Relixr must retain as controller or under law. 8. Enterprise. A negotiated MSA or signed DPA may replace or amend this standard form. Contact: security@relixr.com Full overview: https://relixr.com/trust/dpa