TALLWRIGHT - TERMS OF SERVICE Version terms-1.0. In force from 2026-09-12. Replaces: nothing. This is the first version. The SHA-256 of this file, with CRLF normalised to LF, is published at https://tallwright.com/legal beside this version. 0. THIS DOCUMENT AND THIS VERSION 0.1 The parties. These Terms are the contract between you and: Kyoomee GmbH, a Gesellschaft mit beschraenkter Haftung under Austrian law Seat: Peggau. Address: Grazer Strasse 1/3, 8120 Peggau, Austria Companies register: FN 682788a, Landesgericht fuer Zivilrechtssachen Graz VAT identification number: ATU83518524 Managing directors: David Joebstl, Lukas Muchitsch Contact: hello@tallwright.com. We run no telephone support line. 0.2 Defined terms. "We" and "our" mean Kyoomee GmbH; "you" and "your" mean the business that accepts these Terms. "The Service" is described in clause 3, the "Witness" in clause 6, an "Exhibit" in clause 4. An "Archive" is one record log. An "Operator" is the identity the Witness admits, named by the fingerprint of the key you made. The "DPA" is the Data Processing Agreement, version dpa-1.0, at https://tallwright.com/legal/dpa-1.0.txt. An "Order Form" is a document we and you both sign. 0.3 This version is named terms-1.0. Each version is one plain-text file at its own URL. The page at https://tallwright.com/legal lists these Terms, the DPA, the sub-processor list and the measures annex, links each file at its own URL, and publishes the SHA-256 of each, computed from the bytes served rather than typed. To recompute one, normalise CRLF to LF and hash the bytes. This version names no predecessor, and a superseded version keeps answering at its own URL with its own digest. 0.4 The DPA forms part of this contract; the two change together (clause 23.3). 0.5 English is the authoritative language. Where a deal is conducted in German, the notice that incorporates these Terms and the acceptance label are also given in German; the English text governs. 1. WHO MAY CONTRACT 1.1 The Service is offered to entrepreneurs within the meaning of Section 1 UGB. It is not offered to consumers and is not designed for them. 1.2 You tell us the name of the contracting company and either a VAT identification number or a register number, and keep the name and that number current. Nothing in the product collects them today: until it asks, you give them in writing to hello@tallwright.com, and the payment provider collects a VAT identification number in its own portal. 1.3 A confirmation cannot do this much: your statement that you are a business does not make consumer law inapplicable where it applies. 1.4 If you send us data as a processor for someone else's controller, the DPA applies between us and you, and your own controller's instructions remain your responsibility. 2. HOW THE CONTRACT IS FORMED 2.1 Self-service. The contract is concluded when you accept these Terms in the product. The apply screen links this file and the DPA as files you can read, save and print before you accept, shows the SHA-256 of each, and offers acceptance only through one control naming both; the account-creation screen links both too. 2.2 Managed and Self-Hosted. The contract is concluded by a signed Order Form, which may vary these Terms, including the governing law and venue in clause 27. 2.3 Enrolment. The application your own key signs when you enrol a log carries the name and digest of the version of these Terms and of the DPA you accepted, and the Witness refuses an application whose pairs it does not hold, or that omits a version it does hold. Anyone holding that application can check which text you accepted without asking us. This version's name and digest are pinned in the app's module, the Witness's policy and the notary runbook, all derived from these bytes and held by a test. 2.4 No acceptance row exists in our store yet. When the product writes one it will record the version name, the digest, the time and the browser user agent, and never your IP address or location, because the product stores neither. Such a record is a record, not conclusive proof. 2.5 As between entrepreneurs the information duties in Sections 9 and 10 ECG are excluded. Section 11 ECG is not excluded, and clause 2.1 performs it. 3. THE SERVICE 3.1 What it does. A recorder seals entries you supply into a hash-linked log, and the log's head is presented to the Witness, which cosigns it, signs a refusal, or declines. From a sealed entry you can produce an Exhibit. The Service records what the recorder was given, except that keys on our credential list or reasoning-key list become a redaction marker with the path noted. What else is recorded is your decision, taken as controller. 3.2 The editions are Witness, Self-Hosted, Managed and Cloud. Annex T-1 states for each what runs where, what we receive and what we never receive, and is part of this description. 3.3 Content. We hold no record content for any Archive the product provisions: each holds hashes only and cannot be otherwise, because the provisioning door cannot receive the setting that would create one, and a line carrying a payload, a base64 payload or a subject identifier is refused by name. Two content-holding Archives exist on our fleet host and both are ours - one holds Kyoomee's own records, one is an isolation probe - each with a key database and a content store on disk, read off the host on 2026-09-12. No content-holding tier is offered to customers; offering one would be a new version of these Terms and the DPA. 3.4 Managed. The machine is yours. We watch it and tell you; we do not touch it. Our reporter reads only, opens no port and cannot open an Archive, and what may leave your machine is codes and counts, with no field that could hold the text of a finding. Managed detects silence, not a false report: the reported document is not signed and not bound to the device. 3.5 Two undertakings, owed to you. The verification program is free, needs no account and no registration, and checks an Exhibit offline; we send it on request, to you or directly to the other side. The Exhibit format specification, with its test vectors, is given on request on the same terms. Neither is published yet, and neither is a licence to our software. No third party acquires a contractual claim under these Terms, and clause 20 applies to any claim brought on those two undertakings. 3.6 Availability. We commit no availability figure, uptime percentage or recovery objective. We commit the shape of the failure: if the Witness is unreachable, anchoring degrades rather than lying - a signed proof-of-attempt, every record retained, the head presented again later - and cannot produce an attestation that looks valid. We publish no exposure-window bounds, and while anchoring is unavailable no bound on how long a record stays unanchored holds. 3.7 The one service-level figure. Once a box of yours is enrolled and reporting, for Managed we reply on working days within four hours, measured from the moment our receiver host recorded the report; where that host is itself what failed, the four hours run from when you write to hello@tallwright.com. Working days are Monday to Friday excluding public holidays at our seat. The only other time-bound commitment of ours is the 48 hours in clause 12.1 of dpa-1.0, which is a notification duty and not a service level. The enrolment door on the deployed receiver is not yet in service, and no box but ours has been enrolled. 4. WHAT AN EXHIBIT ESTABLISHES, AND WHAT IT DOES NOT 4.1 Checking an Exhibit establishes two things: (a) the record has not been altered since it was sealed; and (b) it sat at this position in a log of this size. 4.2 It establishes none of these four things: (a) that the record is true; (b) that the log is complete; (c) that the cosigning organization is trustworthy; (d) that the timestamp is a qualified electronic time stamp - it is not one (clause 5). 4.3 Trust inputs come from the reader, never from the Exhibit. What an Exhibit says about who operates the log and which Witness keys to trust is its producer's proposal, to be replaced out of band; the program reads those inputs from a separate policy file and refuses to take them from the Exhibit. 4.4 Two fields lie outside the seal: the anchor receipt and the pointer to a certification. 4.5 The program has four exit codes: 0, valid; 1, invalid; 2, unreadable file or wrong invocation; 3, no verdict, because nothing failed and the reader did not supply enough to decide. Codes 2 and 3 are not verdicts about the evidence and must not be reported as ones. Running it needs no account, licence key, network connection or contact with us; how you obtain it is clause 3.5. 4.6 No proof in this product establishes that a log is complete: an event never captured leaves no trace, and no signature can create one. Completeness is answered by a control you operate. 4.7 The Service does not validate the accuracy of the data recorded. A recorder seals a mistaken entry as faithfully as a correct one. 5. TIME, AND OUR STATUS UNDER eIDAS 5.1 We are a trust service provider within the meaning of Article 3(19) of Regulation (EU) 910/2014 (eIDAS), established in Austria. We are not a qualified trust service provider: we have not been granted that status and are not on the Austrian trusted list with it. None of the presumptions eIDAS reserves for qualified services attaches to anything we produce, and we display no EU trust mark. 5.2 Our supervisory body is the Telekom-Control-Kommission under Section 12(1) SVG, with RTR-GmbH performing the operational tasks. Supervision of a non-qualified provider is ex post. 5.3 What the law does give is Article 41(1) eIDAS: an electronic time stamp is not denied legal effect or admissibility as evidence solely because it is in electronic form or is not qualified. Weight is otherwise a matter for the applicable procedural law. 5.4 The time in an attestation is the Witness's own clock, which runs chrony with NTS, authenticated, against four sources across three organizations - Cloudflare, Netnod and the Physikalisch-Technische Bundesanstalt - verified on that machine on 2026-09-12. 5.5 An Exhibit also carries an RFC 3161 timestamp token over the root. Unless an Order Form names an external timestamp authority, that token is made on the machine that keeps the log, under a certificate that machine makes for itself, and is not independent of the log's operator. 6. THE WITNESS 6.1 The Witness is operated by an organization other than yours, on a machine we administer. An Exhibit in which we are both the log's operator and the cosigner is never a demonstration of organizational separation, and we will not describe it as one. 6.2 What the Witness receives in the body of a request, and nothing else: three lines - origin, tree size, root hash in base64 - your signature over exactly those bytes, and consistency proof material, which is hashes. It never receives records, payloads, plaintext, model output or personal data about your subjects. What it unavoidably learns besides is in clause 6.3. 6.3 What it does learn: the origin string you chose, which may name your own client; the tree size, a record count and over time a volume signal; the time a request arrives and the network address it arrives from, which it records nowhere, because its handler writes no request log; and the enrolment metadata an administrator typed. 6.4 Refusal, and publication. The Witness signs a conclusive refusal where a log presents a head smaller than one already seen, or a different root at a size already held. We may publish such a refusal without your permission, and we will: a witness the witnessed party can silence is not a witness. What is published is the signed refusal itself - origins, sizes, root hashes - never content. We tell you before we publish, and we publish no origin string we know to name a natural person. A refusal is never withdrawn or amended; one with an innocent explanation is answered by a later statement. A decline is unsigned, is not an accusation, and is not published as one. 6.5 Continuity. We give twelve months' written notice before we stop operating the Witness, and a change of control over us does not shorten it. Verification never needs a living Witness: an Exhibit verifies offline against the key directory the reader holds. A successor never inherits the Witness identity and signs with new keys, and the Witness signing key is never escrowed. Escrow of other components is on request. 7. ACCOUNTS, SEATS AND ROLES 7.1 There are two ways to sign in: a one-use link mailed to your address, and a passkey. There is no password. Any external identity provider we connect appears on the sign-in screen and in the sub-processor list. 7.2 Roles are Owner, Admin, Developer and Auditor, read from the membership row on every page. Only an Owner appoints an Owner; an Admin may not invite an Owner; no seat changes its own role or removes itself; an account cannot be left without an Owner. Removing a member revokes their sessions in the same transaction. 7.3 An Auditor is refused every write and sees the account's Archives. A scope recorded on a seat is a label, not an access control, and must not be relied on. 7.4 Letters about money, and notices under these Terms, go to the Owners and Admins. You are responsible for who you admit and for what they do with their seat. 8. WHAT IS YOURS TO DECIDE AND TO DECLARE 8.1 What is recorded is your decision: you decide as controller what a payload may contain, and the product performs no detection or removal of personal data beyond the named-key redaction in clause 3.1. 8.2 You declare what a subject identifier is - opaque, pseudonymous, direct, or undeclared. We record and print that declaration and do not verify it, so an identifier you call opaque may not be one. 8.3 Legal holds. We keep no register of them. You declare a hold on each request that needs it, as a required value with no default, and where an erasure request meets one the conflict goes to a person. 8.4 The statement about your systems and deployment that a court will want is yours to make, as custodian. 8.5 Keys. For an enrolled Operator the browser makes one key, and we admit an Operator without a recovery key; the screen does not ask for one. If you lose the identity key, recording continues and every existing Exhibit keeps verifying; what you lose is the ability to carry the name elsewhere or authorise a different delegate. If you want a recovery key, name it with "tallwright-fleet apply --recovery-key". 8.6 You keep your credentials safe and tell us without delay if one is exposed. 9. ACCEPTABLE USE, AND NOTICES ABOUT CONTENT 9.1 You will not use the Service to store or transmit unlawful content, to infringe a third party's rights, to reach another customer's data, to circumvent our access controls, or to load a shared host so as to threaten other customers' recording. You will not resell the Service as your own unless an Order Form allows it. 9.2 Notices about content go to hello@tallwright.com and should identify the Archive and the record, say why the content is said to be unlawful, and give your contact details. We answer with a statement of reasons naming what we decided and why, and you may reply before we act unless the law requires otherwise. The only act on a record we reserve is clause 16.2, and the only termination for breach of this clause is clause 14.8. Where the content is not ours to hold (clause 3.3) we say so and pass the notice on. 10. FEES, METERING AND INVOICING 10.1 Fees are those in the price list named in Annex T-3. 10.2 What is metered is open Archives, per Archive per month, billed at the month's peak number of open Archives. Records are never charged for, at any volume, and a closed Archive is not billed and not deleted. 10.3 Anchors. Charges under the price list are the per-Archive fees. The anchor rates published with it are the rate that will apply and are not invoiced under it. 10.4 Billing is monthly in arrears over calendar months, in EUR, charged automatically to the payment method on file. The invoice is the provider's, and we never see a card number. 10.5 We serve our own basis for each billed month as a file you can download: one row per measured day, the days measured and the price list identifier, and no amounts. A month with nothing measured produces no basis and says so; a failed measurement is never read as zero. 10.6 A disagreement between the payment provider's records and ours is never resolved against you, and a dunning clock is never started from a vendor's list alone. 11. TAXES 11.1 All figures are exclusive of VAT, and VAT is charged where it is due. Where the conditions for the reverse charge are met, it applies and the tax liability passes to you. 11.2 Where you are registered for VAT you give us a valid identification number and tell us without delay when it changes. If a number you gave us is invalid and tax becomes payable, that tax is yours. The number and the billing address are collected by the payment provider in its own portal. 12. THE FREE ALLOWANCE, AND LIMITS 12.1 Three Archives are free. The allowance belongs to the account and not to any Archive, does not expire, and no payment method is asked for until the fourth Archive. 12.2 A limit never stops a recording: going past what you pay for is recorded and written about, and billed where the price list invoices it (clauses 10.2 and 10.3). 12.3 Where an Archive is over the free allowance we reserve the right to close it after fourteen days' written notice, and a person takes that decision. Nothing is closed automatically and no timer closes anything. A close is permanent: paying afterwards does not undo it, and the Archive stays exportable under clause 15. 13. WHEN A PAYMENT FAILS 13.1 We write to the Owners and Admins on our own clock: on the day the payment first fails, then after seven days, after fourteen days, and on the fifteenth day. 13.2 You have fourteen whole days. From the fifteenth day one thing is withheld: the creation of new Archives. Nothing else changes. 13.3 Everything that exists keeps recording, anchoring and exporting. No key is revoked, nothing is closed and nothing is deleted, on the fifteenth day or the hundredth. The build enforces this: the billing code cannot reach the operations that close or provision an Archive. 13.4 One successful payment lifts the withholding at once. 14. TERM, CLOSING AN ACCOUNT, AND WHAT SURVIVES 14.1 The contract runs monthly with no minimum term. 14.2 There is no self-service close. Closing is requested in writing to hello@tallwright.com and handled by a person, and cancellation is switched off in the payment provider's portal for that reason. This clause does not apply to a termination under clause 23.2. 14.3 On closure, recording stops. Records and Exhibits stay exportable for at least thirty days, and as long as the Archive exists. 14.4 Disposal is per account: the act takes every Archive of that account at once, on your written request and no other way, and it is refused while any of those Archives is open, within thirty days of closure, while any carries a retention class, or under a declared legal hold. A person takes it, from outside the provisioning door. Until you ask, everything stays, and stays exportable under clause 15. Nothing schedules a closure, counts to thirty, or turns a retention label into a date: a retention class you typed holds the Archive until you lift it. Disposal has no undo and is confirmed in writing. 14.5 What is permanent: the Operator identifier, written into every countersignature and Exhibit and surviving closure and renaming; the Witness's admission record and the key it admitted, which sits on the Witness host and is not edited, with a copy in the backoffice that we can neither edit nor invent, only withhold; and a refusal (clause 6.4). 14.6 A closed account reads and exports everything it has and creates nothing. 14.7 We reserve no right to stop recording, anchoring or exporting except on a closure under clause 12.3 or a termination under clause 14.8, and on either, clauses 14.3 to 14.6 apply. The only withholding we reserve is clause 16.1 and the only act on an identified record is clause 16.2. 14.8 Either of us may terminate on thirty days' written notice for a material breach the other does not remedy within that notice. For us, a material breach means a breach of clause 9; unpaid fees are never cause, and clause 13.3 stands. Clauses 14.3 to 14.6 then apply unchanged. 15. EXPORT AND EXIT 15.1 You may export your records, Exhibits and billing basis at any time at no separate charge, including for a closed Archive. Reading your own evidence is never charged. 15.2 An Exhibit link opens once, states its expiry in UTC and cannot be shown again. We keep no prepared copy to serve, and the link itself appears in our edge access log for as long as that log is kept. Nobody needs an account to open it. 15.3 We promise no transitional period and no migration service beyond this clause. In their place: an Exhibit verifies without us, and the format specification is given on request. 15.4 Erasure. On your instruction we destroy, in the live Archive, the subject's key and the salts of that subject's records; the ciphertext then cannot be read, while it and every proof over it stay valid. A restore of the key directory from a backup would bring them back, and the Archive's self-check reports it. So: we restore only on your instruction or to recover from a failure, and we re-apply any erasure already requested after a restore. 15.5 Where an edition you buy is a data processing service within the meaning of Article 2(8) of Regulation (EU) 2023/2854, Chapter VI of that Regulation applies to your exit and prevails over clause 15.3, and we agree the terms it requires on request and at no charge. 16. SUSPENSION, AND THE ONE POWER TO ACT 16.1 The only suspension these Terms allow is the withholding of new Archive creation for non-payment under clause 13.2, and no suspension ever stops a recording, an anchor or an export. 16.2 Where the law requires it, or a court or an authority orders it, we may make an identified record inaccessible. We tell you what we did and why, and every proof over that record stays intact. 17. OUR SOFTWARE, YOUR RECORDS 17.1 tallwright is proprietary and all rights in it are reserved. It is not offered under an open-source licence, in whole or in part; the two undertakings in clause 3.5 stand in place of source availability. 17.2 For the term of the contract we grant you a non-exclusive, non-transferable licence to use the Service and run the packages we ship you, within the edition you bought and for your own business purposes. We do not revoke it while the contract runs (clause 14.7). 17.3 You may not copy, modify, reverse engineer, decompile or disassemble our software, or remove a notice from it, except so far as mandatory law permits and in particular for the purposes of Articles 5(2), 5(3) and 6 of Directive 2009/24/EC. 17.4 Third-party components we distribute are licensed by their own licensors, with their notices in the package. 17.5 Your records, payloads and logs remain yours. We take only the rights we need to run the Service for you, and nothing here lets us use your records for another purpose. The DPA governs personal data and prevails over these Terms for it. 18. CONFIDENTIALITY 18.1 Each of us keeps the other's confidential information confidential, uses it only to perform this contract, discloses it only to people who need it and are bound to the same duty, and protects the other's trade secrets. The duty does not reach information that is public without a breach, already known, independently developed, or required by law to be disclosed; it lasts as long as the information is confidential; and it does not cover a conclusive refusal. 19. WARRANTIES 19.1 We warrant that we provide the Service with reasonable care and skill and that it conforms to the description in clause 3 and Annex T-1. 19.2 Statutory warranty under Sections 922 and following ABGB applies. Where we deliver a package to you, examine it and tell us of a defect within four weeks of delivery; a defect you could not have found on that examination may be notified whenever you find it. 19.3 We give no warranty that a log is complete, and none as to what was recorded being true: those are the limits in clauses 4.2 and 4.6: limits of the product, not disclaimers added to it. 19.4 We hold no security certification, and no third-party security audit or test has been performed. What we have instead is clause 22.5. 20. LIABILITY 20.1 Outside any cap and without limitation of any kind: liability for intent, for personal injury and under product liability law, and anything a mandatory provision makes non-binding, in particular Article 13 of Regulation (EU) 2023/2854. 20.2 Subject to clause 20.1, for gross negligence our liability is capped and is never excluded. The cap is the greater of the fees you paid us under these Terms in the twenty-four months before the event that caused the damage and EUR 50,000. No cap in this clause applies where a mandatory provision makes a limitation non-binding, in particular Article 13(4)(a) of Regulation (EU) 2023/2854 for a data-related term. 20.3 Subject to clause 20.1, for slight negligence the cap is the greater of those fees in the twelve months before that event and EUR 10,000. Indirect and consequential loss is excluded, except loss that consists in the unavailability or unverifiability of a record we undertook to seal, anchor or export. 20.4 A claim must be brought within one year of the day you learned both of the damage and of the person liable. This does not apply to the claims named in clause 20.1, the periods of the Produkthaftungsgesetz are unaffected, and a longer statutory period that cannot be shortened governs. 20.5 Limits on use, for Article 13(2) eIDAS. The limits in clause 4 are notified to you in advance, by this document and by the Exhibit format specification we give on request (clause 3.5). An Exhibit does not carry them, so we claim no limitation of use against a third party who never saw them; as between you and us, we are not liable for damage from use beyond limits so made known to you. 20.6 Under Article 13(1) eIDAS the burden of proving the intention or negligence of a trust service provider that is not qualified lies with the person claiming the damage. 20.7 Your own regulatory, record-keeping and disclosure duties remain yours. 21. SECURITY INCIDENTS 21.1 We tell you without undue delay about a security incident affecting the Service we provide you, in stages rather than waiting for a complete picture: what happened, when we learned of it, what is affected so far as we can tell, and what we did. 21.2 Separately, we notify the supervisory body under Article 19a eIDAS of a breach of security or a disruption with significant impact, without undue delay and within 24 hours, and we notify the people that Article requires. A personal data breach is governed by the DPA. 22. SUB-PROCESSORS AND OTHER THIRD PARTIES 22.1 You give a general authorisation for us to use sub-processors, and we publish a dated list at https://tallwright.com/legal/sub-processors-1.0.txt naming each one, what it does and its country. 22.2 We give the Owners and Admins thirty days' written notice before we add or replace a sub-processor, and you may object within fourteen days. If you object you may terminate the affected part of the contract without penalty, by the route in clause 23.2, and we refund prepaid fees pro rata. Publication on our website is not notice. 22.3 Where things sit today, read from each provider on 2026-09-12. Archives we host are in the EU and do not leave it; on Self-Hosted and on Managed the Archive is on your own machine and its place is yours. The Witness and the fleet host are Hetzner vServers in Falkenstein, Germany (fsn1-dc8), two separate machines in one data centre; the Managed receiver is a Hetzner vServer in Helsinki, Finland (hel1-dc2), deliberately elsewhere. The backoffice is hosted by Vercel, its server code pinned to Frankfurt (fra1), and its database is at Neon, at rest in Amazon Web Services eu-central-1, Frankfurt - so Amazon holds those bytes - with point-in-time history as stated in the measures annex and no copy anywhere else. Product mail goes out through Resend, inbound mail and DNS are at World4You in Austria, our public edges take certificates over ACME from the issuers our web server is configured with - Let's Encrypt, with ZeroSSL as that server's default fallback, no issuer pinned - and payments are at Stripe, whose contracting entity is the one its own terms state, as stated by the provider and not verified by us. For Vercel, Neon and Resend the legal entity and parent domicile are not verified by us. 22.4 Off-host backups. The fleet host backs up every Archive on it; the Managed receiver backs up only its roster - per box, the hash of its key and the silence interval - and never a receipt and never a reported document. Both are encrypted on the host before they leave, and are not searched or edited. The destination is a storage service of Hetzner Online GmbH in Germany, reached over SFTP; that repository is not append-only, we make no immutability claim about it, and no restore has been rehearsed. The Witness host has no backup script at all, and the backoffice store has only its provider's point-in-time history. 22.5 Audits. On request we give you a completed security questionnaire, the measures annex at https://tallwright.com/legal/toms-1.0.txt, and the tests that hold each statement in it. You may inspect on site once a year on thirty days' notice, at your cost unless it finds a material failure, in which case we bear it. We restrict no supervisory authority. 23. CHANGES 23.1 To the Service. We may change the Service, but not so as to reduce a property these Terms or Annex T-1 state except under clause 23.2. We give advance notice before the regions in which your data is processed or stored change. 23.2 To these Terms. A change takes effect thirty days after we notify the Owners and Admins, and only for one of these reasons: a change in law or in supervisory practice; a change to the Service described in Annex T-1; the addition or replacement of a sub-processor; the correction of an error or an ambiguity; or a new price list. Before it takes effect you may terminate at no cost, with prepaid fees refunded pro rata. A termination on a change of these Terms or of the price list, or on an objection under clause 22.2, is made by writing to hello@tallwright.com; it takes effect on receipt, needs no reason and no notice, stops the next charge, and clause 14.2 does not apply. 23.3 A change is always a new file: a new name, a new digest, the predecessor's digest named. These Terms and the DPA change together, because the Witness holds both version names at once and refuses an application omitting either, so there is no overlap window and no staggered release. 23.4 For an enrolled operator the version that governs is the one named inside the bytes your own key signed, until you publish a new application. 24. FORCE MAJEURE 24.1 Neither of us is liable for a failure caused by an event outside its reasonable control, for as long as it lasts, and the affected party says so promptly. 24.2 This clause does not cover what our own measures address: the Witness being unreachable (clause 3.6) or the loss of a machine we operate. It never excuses a failure to let you export under clause 15. 25. ASSIGNMENT AND CHANGE OF CONTROL 25.1 We may assign this contract to a successor to the business, on notice to you. You may assign with our written consent, not unreasonably withheld. Clause 6.5 is unaffected by a change of control over us. 26. NOTICES 26.1 Notices to us go to hello@tallwright.com; notices to you by email to the Owners and Admins, and you keep one such address current. 26.2 Product mail is sent from a no-reply address, so a reply to it does not reach us. A notice sent by email takes effect on the next working day. 27. GOVERNING LAW AND VENUE 27.1 Austrian law applies. The United Nations Convention on Contracts for the International Sale of Goods (CISG) is expressly excluded. 27.2 The court with subject-matter jurisdiction for our seat has exclusive jurisdiction over every dispute arising out of or in connection with this contract, including its existence and validity. This is expressly agreed between entrepreneurs. Where you enrol an Operator, the version and digest of these Terms sit inside the bytes your own key signed, and that document evidences this agreement for Section 104(1) JN; for a self-service account with no enrolment we do not rely on this clause where that provision requires proof by document. Nothing here displaces a jurisdiction a mandatory provision assigns elsewhere. 27.3 A signed Order Form may vary 27.1 and 27.2; where a regulated customer requires its own law or forum, that is a negotiated deviation, not a defect in this clause. 28. SEVERABILITY AND ORDER OF PRECEDENCE 28.1 If a clause is invalid or unenforceable the rest stands, and we will agree a replacement as close to its purpose as the law allows. 28.2 Order of precedence, highest first: a signed Order Form; Annex T-2, for a financial entity that has signed it; the DPA, for personal data; these Terms; Annex T-1; Annex T-3. 28.3 Five clauses are pointed out specially because they are the easiest to miss: the publication of a conclusive refusal in clause 6.4, without your permission, naming the origin string you chose, never withdrawn; the liability cap in clause 20; the exclusive venue in clause 27.2; the amendment mechanism in clause 23.2, under which a change takes effect if you do not terminate; and the effect of closure on your evidence in clause 14. Saying so does not make a clause part of the contract that the law keeps out of it. ANNEX T-1 - THE FOUR EDITIONS WITNESS Runs where: nothing of ours on your machines; the cosignature service on our machine in Falkenstein. We receive: per request, three lines - origin, tree size, root hash in base64 - your signature over those bytes, and hash-only proof material, plus the request's arrival time and the network address it arrives from, which is recorded nowhere; the enrolment metadata; a per-month count of anchor requests per log, with no time of day. We never receive: records, payloads, plaintext, model output, subject identifiers, or personal data about your subjects. SELF-HOSTED Runs where: everything on your machines, operated by you; nothing of ours in your estate. The shipped packages make no network call of their own: the only outbound connections are to a Witness address and a timestamp URL you configure. We receive: nothing, unless you also buy Witness, in which case the Witness lines apply. We never receive: any record, payload or operational data about your deployment. MANAGED Runs where: the Archives on your own machine; our reporter there, read-only and unable to open an Archive; our receiver in Helsinki. We receive: codes and counts - a closed set of finding codes and two integers per box - plus the newest accepted document per box, kept with no history; in the backoffice, the account, contact addresses and sealed credentials for your Archive. We never receive: record content, payloads, subject identifiers, or the text of a finding. CLOUD Runs where: the Archives on our fleet host in Falkenstein, operated by us; the backoffice in Frankfurt. We receive: record hashes, leaf and root material, anchor state, and the account and billing data in the backoffice. We never receive: record content, on the terms and for the reasons in clause 3.3. ANNEX T-2 - FINANCIAL ENTITIES T-2.1 This annex applies where you are a financial entity within the meaning of Regulation (EU) 2022/2554 (DORA) and have signed it. The contract is then concluded by a signed Order Form incorporating these Terms, the DPA and this annex, so the arrangement sits in one set of documents, each named with its digest and provided together in durable downloadable form, as Article 30(1) DORA requires. T-2.2 Editions. All four editions in Annex T-1 are available to a financial entity, and no content-holding tier is offered to anyone (clause 3.3). Where the service supports a critical or important function, T-2.4 is required as well. T-2.3 The items of Article 30(2) DORA, answered as the Service is: (a) Description and subcontracting: clause 3, Annex T-1, clause 22. (b) Locations: clause 22.3, per edition, with notice of a change under clause 23.1. (c) Availability, authenticity, integrity and confidentiality of data: the measures annex, which states each measure and what enforces it; availability is clause 3.6. (d) Access, recovery and return of data, including on our insolvency or discontinuation: clause 15 (export at no charge, closed Archives included), verification without a living Witness, the format specification on request, twelve months' notice under clause 6.5, escrow on request. (e) Service levels and their updates: clauses 3.6 and 3.7, changed only under clause 23.2. (f) Assistance during an ICT incident: clause 3.7 at no additional cost; further assistance at a rate fixed in advance in the Order Form, never after the incident. (g) Cooperation with authorities: full, and we restrict no supervisory authority. (h) Termination rights and notice periods: clauses 14, 22.2, 23.2 and 6.5. (i) Security awareness and resilience training: we take part in your programme at the cost agreed in advance in the Order Form. T-2.4 Article 30(3) DORA is a separate, priced addendum: quantitative and qualitative performance targets, tested contingency planning, participation in your threat-led penetration testing, unrestricted rights of access, inspection and audit, and an exit strategy with a mandatory transition period are priced separately and not covered here. T-2.5 Two things a reviewer will ask. First, clause 19.4: no security certification, no third-party security audit or test. Second, we are not a designated critical ICT third-party service provider under DORA. These terms are aligned to Article 30(2); using the Service does not make you compliant with DORA, NIS2 or Regulation (EU) 2024/1689, and those obligations remain yours. ANNEX T-3 - THE PRICE LIST T-3.1 The price list in force for this version is the list identified as 2026-08-24, which we give you in writing on request. That identifier is written into every month we bill, so an invoice stays answerable against the list it came from. T-3.2 A change to any figure is a new price list with a new identifier and date, published before it applies, and a new price at the payment provider. An existing price list is never edited. T-3.3 The anchor rates published with the list are the rate that will apply and are not invoiced under it (clause 10.3).