TALLWRIGHT - SUB-PROCESSOR LIST Version sub-processors-1.1. In force from 2026-09-13. Replaces: 6302c066e9d13190f030a412efbdbc4b4a25c68b886644afc97ba55d899a9043 The SHA-256 of this file, with CRLF normalised to LF, is published at https://tallwright.com/legal beside this version. What changed from 1.0: - nothing in the text. Re-issued so that one version covers all four documents, as - clause 0.5 of the Agreement describes. Annex C to the Data Processing Agreement (dpa-1.0). Processor: Kyoomee GmbH, Grazer Strasse 1/3, 8120 Peggau, Austria. FN 682788a, Landesgericht fuer Zivilrechtssachen Graz. UID ATU83518524. hello@tallwright.com "We" is Kyoomee GmbH and "you" the customer; other terms mean what terms-1.0 and dpa-1.0 say. English is authoritative; a deal conducted in German gets a German incorporation notice. 0. Status of this list 0.1 It names every company we engage that receives data of yours, what each does and where; one reached only through another is named in that provider's entry (1.2). Accurate at the date above. 0.2 Publishing a new version of this list is not notice of a change. Notice is the letter in section 6. dpa-1.0 governs which version of this list is in force, and nothing published here varies that agreement. 1. Processors of personal data 1.1 Backoffice hosting - Vercel (legal entity and parent domicile not verified by us). The website and the backoffice: everything the backoffice holds passes through it, in the categories of Annex A.4 of dpa-1.0 in full - passkeys, invited addresses, audit events with the actor's address, applications, a copy of the witness's admissions register we can neither edit nor invent but could withhold, and your fleet address and credentials, encrypted under a key in its own deployment environment, so it holds both halves and the provider in 1.2 neither. Server code is pinned to Frankfurt (fra1), read from the response headers on 2026-09-12 and held by a test; builds, platform logs and the marketing site pin no region, and the site holds no personal data. 1.2 Backoffice database - Neon (legal entity and parent domicile not verified by us). The data in 1.1 at rest in Amazon Web Services' Europe Central 1, Frankfurt - so Amazon holds those bytes; read in Neon's console on 2026-09-11. 1.3 Outbound product mail - Resend (legal entity and parent domicile not verified by us). The recipient address, the subject, and a plain-text body that can carry a one-use sign-in or invitation link, account names, operator identifiers, register entry numbers and the sentence an Exhibit bears. No HTML part, no tracking parameter; processing in the EU on that provider's own statement, with no region selected by our code. 1.4 Payments - Stripe. A customer name or operator identifier, an e-mail address, account metadata, a monthly quantity. Card, billing address and VAT identification number are typed in Stripe's own single-use portal session; our product has no card field and collects no invoicing entity, VAT or register number. The contracting entity is the one Stripe's own terms state, as stated by that provider and not verified by us; as at 2026-09-12 no live payment has been taken. 1.5 The machines - Hetzner Online GmbH, Germany. Three vServers, plus the storage in 1.6. The witness and the fleet host carrying hosted Archives are separate machines: the fleet and receiver installers each refuse to run on a machine holding one of the others, and verify-isolation takes a host's word for nothing. Those two sit in one datacentre in Falkenstein, Germany (fsn1-dc8), the Managed receiver in another, in Helsinki, Finland (hel1-dc2) - read from the provider's metadata service on 2026-09-12. Hetzner holds no credential to any door of ours, but runs the machines and storage, unencrypted at volume level: see toms-1.0 section 1. 1.6 Off-host backup storage - Hetzner Online GmbH, Germany, the same provider as 1.5: a Storage Box in Germany, reached over SFTP. The fleet host pushes every Archive on it; the receiver pushes only its roster (2.3), never a receipt or telemetry document; the witness host pushes nothing, and the backoffice store has only its provider's own history. Both pushes are encrypted on the host before they leave, unsearched and unedited. No payload of yours and no subject identifier is there, because every Archive the product provisions is hashes-only (2.4). The repository is not append-only: a host's credential can delete what that host wrote. Whether provider-side snapshots stand beneath it, under an account the host cannot reach, is part of provisioning the destination; nothing of ours verifies it, so none is asserted, and no restore has been rehearsed. Its address and topology are unpublished; you get them under clause 13.1 of dpa-1.0. 1.7 DNS and inbound mail - World4You, Austria. DNS for tallwright.com and the mailbox for hello@tallwright.com, so it receives what you write to us: operator identifiers, account names, enrolment commands. Its legal entity is not established and not guessed here (8.1). 1.8 Identity providers - none configured. Production offers a one-use emailed link and a WebAuthn passkey in your own browser. The code ships Google and GitHub connectors, neither configured in production, and any we connect appears on the sign-in screen and in this list (section 6). 1.9 Place of processing. Archives we host are in the EU and do not leave it. On Self-Hosted and on Managed the Archive is on your own machine and its place is yours. We have read none of these providers' own data protection terms, so no transfer mechanism is asserted here - not the Commission's Standard Contractual Clauses, not anything else. 2. What each Edition reaches 2.1 Self-Hosted. Nothing in section 1, except 1.1 to 1.4 for account data if you hold an account. No service of ours runs in your estate and nobody of ours can reach it; the software you run is yours to operate, and nothing we ship calls out but to a witness address and a time-stamping URL you configure. 2.2 Witness. The witness machine (1.5), the time operators (3.2), 1.1 to 1.4 for account data. It receives three lines, a signature over them and hash-only proof material, plus origin string, log size, arrival time and enrolment data - no record, payload, payload address or subject identifier. It learns the network address a request arrives from and records it nowhere: its handler writes no request log. 2.3 Managed. As 2.2, plus the receiver host in Helsinki (1.5) and the storage in 1.6. Per box it accepts a key hash and never a key, four moments, two counts and closed-set status codes, keeping only the newest accepted document; its roster - key hash, start of watching, your silence threshold - goes to 1.6, the documents not. We hold no copy of your Archives; our reporter there only reads, opens no port and cannot open an Archive. It has run only on machines of ours: as at 2026-09-12 the enrolment door does not work yet and no third party's box is enrolled; the four-hour working-day reply applies once a box of yours is enrolled and reporting. 2.4 Cloud, hashes-only. As 2.2, plus the fleet host (1.5), the storage in 1.6 and the certificate authorities (3.1). Every Archive the product provisions is hashes-only and cannot be otherwise: the provisioning door lacks the variable that would create a content-holding book, and a payload or subject identifier is refused by name. Two books there do carry holds-content custody, both ours - Kyoomee's records and an isolation probe, read off the host on 2026-09-12. No Archive of yours there holds content. 2.5 In every Edition, no payload and no subject identifier reaches 1.1 to 1.4. What the backoffice reads from your fleet host and renders without keeping is record metadata - record ids, times, event and action types, payload hashes, actor authority, legal hold - and, per Archive, the origin string you composed, your organization name, the retention label, closures and counts. An origin string is yours to compose and can identify a person; nothing here requires one that does. 3. Infrastructure third parties with no personal data of yours 3.1 Certificate authorities. On the hosts in 1.5 the web server names no issuer in our configuration, so the issuer is that server's default chain - Let's Encrypt, operated by the Internet Security Research Group, United States, with ZeroSSL as the fallback - which receives the public hostnames, the host address and an operations e-mail address. The website and backoffice edges are certificated by the platform in 1.1 under its own ACME account; no issuer is pinned anywhere and Certificate Transparency shows which signed. The witness uses none, by design - one could authorise a substitute witness - and you authenticate its self-signed certificate with an out-of-band key pin. 3.2 Network time - Cloudflare (United States), Netnod (Sweden) and the Physikalisch-Technische Bundesanstalt (Germany's national metrology institute). The witness's clock is chrony with NTS, authenticated, against four sources run by those three organizations; an unauthenticated source cannot be selected. Verified live with chronyc on 2026-09-12. 4. Build and supply chain These touch code, not your data, so an addition is not a sub-processor change; one that ever receives personal data of yours moves to section 1, under section 6. GitHub, Inc. (Microsoft, United States) holds the private repository and runs the build checks, which Vercel's integration reads to deploy. Package sources: PyPI, the npm registry, Cloudsmith and the Debian and Ubuntu mirrors; how each is pinned is toms-1.0 section 1. 5. Deliberately absent 5.1 We are not a qualified trust service provider. No external time-stamping authority is in the anchoring path of any deployment we run: each mints its own time-stamping certificate and an exhibit says so. A Self-Hosted operator who configures a time-stamping URL puts one in their own path; that provider is theirs, not ours, and is not a sub-processor of ours. No transparency-log service, no blockchain. 5.2 No analytics, advertising tracker or error-reporting component in either web application, and no third-party asset loads while a page is open - fonts resolve at build time; checked 2026-09-12, no gate holds it. 5.3 No AI provider is a third party of ours: the hosts your agent calls are yours and appear in our recorder as hosts it called, credentials dropped by an allowlist from headers and query strings and, for the two hosts whose whole path is a secret, from the path - each record stating which applied. 6. Changes and objections 6.1 You authorise us to use these sub-processors and to add or replace one. At least thirty days before a new one begins processing, we write to every Owner and Admin on your account, naming the company, its role, its country and the date. Where a provider fails or must be replaced to avoid a material risk, we may replace it sooner, writing the same day with the reason; your rights below run from that letter. We have never done this as at 2026-09-12. 6.2 You have fourteen days from receipt to object in writing, stating your reason. The period runs from the day an address we must write to receives it, and does not start if none does. Silence for fourteen days authorises that change and nothing else. 6.3 While an objection is open that sub-processor does not process your personal data, and we answer within fourteen days: we keep your data away from it, or say we cannot and you may then terminate the affected part without penalty by writing to hello@tallwright.com, effective on receipt, under clause 23.2 of terms-1.0, with prepaid fees for the unused remainder refunded pro rata. Recording never stops, and records, exhibits and the usage basis export free. 7. Where this list appears, and how to check it 7.1 The same list is Annex C to dpa-1.0. Quoted or summarised anywhere else, this file governs; nothing we publish varies dpa-1.0. The apply and account-creation screens both link https://tallwright.com/legal, where this file, its digest and all four documents are published. The apply screen shows terms-1.0 and dpa-1.0 with their digests and takes acceptance through one control naming both, before anything is signed; this annex and toms-1.0 are incorporated by name and URL, never by digest, so a change here is not a change to what the witness must accept. 7.2 Most entries can be checked without us: Certificate Transparency for our certificates, a DNS query for tallwright.com, each provider's own sub-processor list and region pages. Two come from us: the Witness Practice Statement, for the clock sources and the dated readings behind 1.5; and the verification program for what a time stamp asserts - free, to either side, with the Exhibit format specification and test vectors. Each company's registered office, data protection contact and identifier on request. 8. Versions 8.1 sub-processors-1.0, in force from 2026-09-12 with terms-1.0 and dpa-1.0. Five values are unresolved rather than guessed: the Stripe contracting entity (1.4) and the legal entities behind Vercel (1.1), Neon (1.2), Resend (1.3) and World4You (1.7); for the first three the parent domicile is unverified too. There is no signed version of this annex - dpa-1.0 incorporates this file as Annex C - so such a value resolves in a new version. 8.2 Every later version has its own name and URL, which keeps answering after supersession, names its predecessor's SHA-256 and what changed. Which version is in force as Annex C is governed by dpa-1.0 and not by this file: it is the most recent one notified under clause 7.3 of that agreement and published at https://tallwright.com/legal. Publishing a version is not what puts it in force (0.2).