Legal

Data Processing Agreement

Version 1.1 · Effective: 21 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Regulatory Knowledge Europe AB (“BARK”) and the customer (“Customer”) governing the Customer's use of BARK services.

This DPA applies where BARK processes Personal Data on behalf of the Customer in connection with the Service.

Where the Customer accepts BARK's General Terms and Conditions through an online checkout, order process or other electronic means, this DPA is incorporated into and forms part of that agreement where applicable.

1. Scope and Application

This DPA governs BARK's Processing of Personal Data on behalf of the Customer in connection with the Service.

The subject matter, nature, purpose and duration of the Processing, as well as the categories of Data Subjects and Personal Data, are described in the applicable Schedule. Schedule 1 applies to BARK Regulatory Research. Schedule 2 applies to BARK Reporting.

If there is a conflict between this DPA and the General Terms and Conditions regarding the Processing of Personal Data on behalf of the Customer, this DPA will prevail to the extent of that conflict.

2. Roles of the Parties

Where BARK Processes Personal Data on behalf of the Customer:

The Customer is responsible for ensuring that its instructions to BARK comply with applicable Data Protection Law and that it has an appropriate legal basis for the Processing.

3. Processing Instructions

BARK will Process Personal Data only:

The Customer's use and configuration of the Service, together with the applicable agreement and this DPA, constitute documented instructions to BARK.

If BARK believes that an instruction infringes applicable Data Protection Law, BARK will inform the Customer unless prohibited by law.

4. Confidentiality

BARK will ensure that persons authorised to Process Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Personal Data will be limited to situations where access is reasonably necessary to provide, support, maintain or secure the Service, investigate incidents, or comply with applicable legal obligations.

5. Security

BARK will maintain appropriate technical and organisational measures designed to protect Personal Data, taking into account the nature, scope, context and purposes of the Processing and the risks to individuals.

BARK may update its technical and organisational measures as its technology and Service develop, provided that such updates do not materially reduce the overall level of protection applicable to Customer Personal Data.

Customer-specific security requirements may be agreed separately where appropriate.

6. Subprocessors

The Customer provides BARK with general written authorisation to engage Subprocessors where necessary to provide the Service.

BARK will require Subprocessors that Process Customer Personal Data to be subject to data-protection obligations appropriate to the Processing they perform.

BARK will maintain information regarding its relevant Subprocessors and will provide reasonable advance notice of material additions or replacements, where reasonably practicable.

BARK aims to provide at least 30 days' prior notice of such changes where reasonably practicable. A shorter period may apply where a change is reasonably necessary for security, legal, availability or other urgent operational reasons.

The Customer may raise a reasonable data-protection objection to a new Subprocessor during the applicable notice period.

The parties will seek to resolve such objection in good faith. Where no reasonable solution is available, either party may terminate the affected Service in accordance with the applicable agreement.

7. International Transfers

Where BARK Processes Customer Personal Data outside the European Economic Area, BARK will use an applicable transfer mechanism or other appropriate safeguard where required by Data Protection Law.

This may include an adequacy decision, applicable standard contractual clauses or another legally recognised transfer mechanism.

Customer-specific requirements relating to international transfers may be agreed separately.

8. Data Subject Rights

Taking into account the nature of the Processing, BARK will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under applicable Data Protection Law.

If BARK receives a request directly concerning Customer Personal Data for which the Customer is the Controller, BARK may direct the individual to the Customer unless BARK is legally required to respond directly.

9. Personal Data Breaches

BARK will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

BARK will provide information reasonably available to it that is relevant to the Customer's assessment and fulfilment of applicable breach-notification obligations.

BARK's notification of a Personal Data Breach does not constitute an acknowledgement of fault or liability.

10. DPIAs and Regulatory Cooperation

Taking into account the nature of the Processing and information available to BARK, BARK will provide reasonable assistance to the Customer with:

Such assistance will be proportionate to BARK's role as Processor and the Processing performed through the Service.

11. Return and Deletion

Following termination or expiry of the relevant Service, BARK will, subject to applicable law and the technical operation of backup and recovery systems, delete or return Customer Personal Data in accordance with applicable Customer instructions and the Service's applicable data-handling processes.

BARK may retain Personal Data where required by applicable law. Any Personal Data retained for such purposes will remain subject to the protections of this DPA for as long as it is retained.

Personal Data may remain temporarily in backups or recovery systems following deletion from active systems until those systems are overwritten or otherwise processed in accordance with applicable retention processes.

12. Compliance Information and Audits

BARK will make available information reasonably necessary to demonstrate compliance with its obligations as Processor under applicable Data Protection Law.

Where reasonably sufficient, BARK may satisfy this obligation through documentation, responses to reasonable information requests and relevant independent reports or certifications where available.

Where such information is not reasonably sufficient, or where otherwise required by applicable Data Protection Law, the Customer may request an audit subject to reasonable advance notice and appropriate confidentiality, security and operational requirements.

Audits must not unreasonably interfere with BARK's operations or compromise the security, confidentiality or data of BARK or other customers.

13. Liability

The liability of each party arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the applicable General Terms and Conditions, Order Form or other agreement between the parties, except to the extent such limitation is prohibited by applicable law.

14. Term and Termination

This DPA takes effect when it becomes applicable to the Customer's use of the Service and remains in effect for as long as BARK Processes Customer Personal Data on behalf of the Customer.

Obligations that by their nature must continue after termination, including applicable confidentiality and data-protection obligations relating to retained Personal Data, will survive termination for as long as necessary.

15. Governing Law

This DPA is governed by the same governing law and jurisdiction as the agreement governing the Customer's use of the Service.

Unless otherwise agreed, that is Swedish law and the courts specified in BARK's General Terms and Conditions.

16. Contact

Questions relating to this DPA or BARK's Processing of Customer Personal Data may be directed to:

Regulatory Knowledge Europe AB
Registration number: 559536-9876
Birger Jarlsgatan 57
113 56 Stockholm
Sweden

Email: info@barktechnologies.se

Schedule 1 — Details of Processing, BARK Regulatory Research

Service

BARK Regulatory Research

Subject Matter

Processing of Personal Data where necessary for BARK to provide Regulatory Research and related service functionality to the Customer.

Duration

For the duration of the Customer's use of the relevant Service and any subsequent period during which Personal Data is retained in accordance with the agreement, this DPA, applicable law and BARK's applicable retention processes.

Nature and Purpose of Processing

Processing may include receiving, transmitting, storing, organising, retrieving, analysing and otherwise Processing Personal Data as necessary to:

Categories of Data Subjects

Depending on Customer use, Personal Data may relate to:

Categories of Personal Data

Depending on Customer use, Personal Data may include:

Sensitive and Special Category Data

BARK Regulatory Research is not designed for the Processing of special categories of Personal Data or other highly sensitive personal information unless expressly agreed otherwise.

Customers should avoid submitting such information through Regulatory Research where it is not necessary for the intended use of the Service.

Processing Locations and Transfers

Processing may take place within the EEA and, where relevant to the provision of the Service, in other jurisdictions subject to the safeguards described in this DPA and applicable Data Protection Law.

Subprocessors

BARK may use Subprocessors in accordance with Section 6 of this DPA.

Information regarding relevant Subprocessors is maintained separately by BARK.

Schedule 2 — Details of Processing, BARK Reporting

Service

BARK Reporting, and any delivery of a reporting solution agreed with the Customer

Subject Matter

Processing of Customer Personal Data contained in data the Customer submits for regulatory reporting, and of data about the Customer's users.

Duration

For the term of the agreement, followed by return or deletion under Section 11 of this DPA.

Nature of Processing

Storage, structuring, mapping and classification (including with AI-assisted tools), aggregation, calculation, validation and generation of regulatory reports and related files.

Purpose

To provide BARK Reporting and any delivery of a reporting solution agreed with the Customer, including testing, reconciliation and support. BARK does not use Customer Personal Data to train, fine-tune or evaluate models.

Categories of Data Subjects

The Customer's borrowers, depositors and other customers, guarantors and connected persons where relevant for reporting, and the Customer's employees and contractors who use the service.

Types of Personal Data

Customer and contract identifiers; where included in submitted data, personal identity numbers; account, loan and deposit data such as balances, interest rates, maturities and currency; credit risk data such as days past due, default status, impairment stage and forbearance; counterparty classification such as sector and residence; for users, name, email address, login and activity logs.

Special Categories

None. The Customer shall not submit special categories of personal data or personal data relating to criminal convictions.

Data Minimisation

The Customer should submit pseudonymised identifiers wherever direct identifiers are not required for the report concerned.

Location

As set out in the information on Subprocessors maintained by BARK under Section 6 of this DPA.