DATA PROCESSING AGREEMENT Effective Date: August 14, 2026 This Data Processing Agreement ("DPA") is entered into between: Data Controller: The individual or entity using Evalanta services Data Processor: Evalanta Ltd. 1. DEFINITIONS 1.1 "Data Protection Laws" means all laws and regulations relating to data protection and privacy, including the General Data Protection Regulation (GDPR), the Australian Privacy Act 1988, and any implementing or supplementary legislation. 1.2 "Personal Data" means any information relating to an identified or identifiable natural person processed by Evalanta on behalf of the Controller. 1.3 "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion. 2. SCOPE AND PURPOSE 2.1 This DPA applies to all Processing of Personal Data by Evalanta in connection with the provision of services to the Controller. 2.2 Evalanta shall Process Personal Data only for the purposes of providing educational platform services, including: - User account management - Course delivery and progress tracking - Payment processing - Communication with users - Analytics and improvement of services 3. DATA CONTROLLER OBLIGATIONS 3.1 The Controller warrants that: - It has obtained all necessary consents and authorizations for Processing - Personal Data provided complies with Data Protection Laws - It has provided appropriate privacy notices to data subjects 4. DATA PROCESSOR OBLIGATIONS 4.1 Processing Instructions: Evalanta shall Process Personal Data only in accordance with documented instructions from the Controller, including as specified in this DPA and the Terms of Service. 4.2 Confidentiality: Evalanta ensures that persons authorized to Process Personal Data have committed themselves to confidentiality. 4.3 Security Measures: Evalanta implements appropriate technical and organizational measures: - Encryption in transit (TLS 1.3) and at rest (AES-256) - Role-based access controls - Regular security assessments - Automated backups with point-in-time recovery - Multi-factor authentication for administrative access 4.4 Subprocessors: Evalanta may engage subprocessors as listed in the Trust Center. Evalanta maintains a current list at https://evalanta.com/trust and notifies the Controller of any changes. 4.5 Data Subject Rights: Evalanta shall assist the Controller in responding to data subject requests regarding access, rectification, erasure, and data portability. 4.6 Data Breach Notification: Evalanta shall notify the Controller without undue delay (within 72 hours) upon becoming aware of any Personal Data breach. 4.7 Data Protection Impact Assessment: Evalanta shall provide reasonable assistance to the Controller with data protection impact assessments. 5. INTERNATIONAL TRANSFERS 5.1 Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA) and Australia. 5.2 For transfers from the EEA, Evalanta ensures appropriate safeguards are in place, including Standard Contractual Clauses where required. 5.3 For transfers from Australia, Evalanta complies with Australian Privacy Principle 8 (cross-border disclosure). 6. DATA RETENTION AND DELETION 6.1 Personal Data shall be retained only as long as necessary for the purposes specified in Section 2. 6.2 Upon termination of services, Evalanta shall delete or return Personal Data in accordance with the Controller's instructions, except where retention is required by law. 6.3 The Controller may request deletion of Personal Data at any time through the platform's data export/deletion features. 7. AUDIT RIGHTS 7.1 Evalanta shall make available to the Controller all information necessary to demonstrate compliance with this DPA. 7.2 Upon reasonable notice, Evalanta shall allow for audits and inspections by the Controller or an independent auditor. 8. LIABILITY 8.1 Evalanta's liability for breaches of this DPA shall be subject to the limitations set forth in the Terms of Service. 8.2 Where both Evalanta and the Controller are responsible for damage caused by Processing, liability shall be apportioned according to their respective responsibility. 9. TERM AND TERMINATION 9.1 This DPA shall remain in effect for the duration of the service agreement between the parties. 9.2 Either party may terminate this DPA with 30 days written notice if the other party materially breaches its obligations. 10. GOVERNING LAW 10.1 This DPA shall be governed by the laws of [JURISDICTION], without regard to conflict of laws principles. 10.2 For Australian customers, this DPA is subject to the Australian Privacy Act 1988 and related legislation. 10.3 For customers in the European Union, this DPA is subject to the GDPR and applicable member state laws. 11. CONTACT INFORMATION For questions regarding this DPA: Email: legal@evalanta.com Address: Evalanta Ltd., [Registered Address] --- This Data Processing Agreement is available at: https://evalanta.com/legal/dpa.pdf Last updated: August 14, 2026 © 2026 Evalanta Ltd. All rights reserved.