# Software-as-a-Service Agreement

**Version 1.5 — August 21, 2026**

## Preamble

This Software-as-a-Service Agreement (hereinafter the "SaaS Agreement") constitutes an integral part of the agreement concluded between Square8 Technologies AG (hereinafter "Square8"), with registered office at Beethovenstrasse 48, 8002 Zürich, Switzerland (VAT number CHE-331.221.308), and the customer (hereinafter the "Customer").

The Customer is defined in the Order Form by its address and tax ID. Square8 and the Customer are hereinafter individually referred to as a "Party" and collectively as the "Parties."

Square8 has developed an AI workforce platform that lets companies hire, train, and deploy AI Workers into defined roles, and provides it to its customers. The Customer intends to use the services of Square8 (each as defined below) for its business operations. Square8 offers the services under the terms and conditions set out in this SaaS Agreement and the Order Form. The Customer agrees to use the services in accordance with the provisions of this Agreement and undertakes to pay the corresponding fees. Unless otherwise agreed, the Services are provided on Square8's standard, shared servers and infrastructure; any customer-specific setup, such as a private or dedicated deployment (e.g. a private Claude/LLM instance), must be expressly specified in the Order Form. Test Customers who access or use the Platform or Services on a trial, demo, or evaluation basis without having signed an Order Form do not receive the rights, warranties, service levels, or other protections granted under this SaaS Agreement or its Annexes; such access is governed exclusively by Annex G (Test Customers Without an Order Form).

## 1. Definitions

1.1 "AI Worker" means an AI Worker that is hired and activated by the Customer in a role during the respective calendar month.

1.2 "Order Form" means the document defining the conditions for the Customer's access to the platform, the fees, the product description, and customer-specific information.

1.3 "Effective Date" means the date on which the Order Form is signed by the Customer.

1.4 "Fees" means all payments to be made by the Customer to Square8 as specified in the Order Form.

1.5 "Intellectual Property Rights" include, among others, patents, copyrights, trademarks, and know-how.

1.6 "Business Hours" are Monday to Friday, 9:00 a.m. to 5:00 p.m., excluding public holidays at Square8's registered office.

1.7 "Customer Data" means all content, data, or information provided by the Customer.

1.8 "Partners" are third parties engaged by Square8 to support sales, implementation, or the provision of services.

1.9 "Personal Data" means information as defined in Art. 4 No. 1 GDPR or Art. 5 of the Swiss Data Protection Act (DSG).

1.10 "Platform" means the Square8 web application and its modules.

1.11 "Service" means all services provided by Square8 under this Agreement.

1.12 "Affiliated Companies" means companies within the meaning of applicable law belonging to the corporate group of Square8 or the Customer.

1.13 "Confidential Information" means non-public information that is marked as confidential or that can reasonably be considered confidential.

1.14 "Prompt Injection" means any attempt to manipulate, override, or bypass the intended behavior, instructions, or security controls of the AI Worker or its underlying language models by embedding hidden, disguised, or adversarial instructions within content, data, files, documents, websites, emails, API responses, or any other input processed by the Services, with the intent or effect of causing the AI Worker to perform unauthorized actions, disclose confidential or restricted information, circumvent access controls, or act contrary to Square8's or the Customer's instructions.

1.15 This SaaS Agreement is only complete together with all Annexes hereto, which form an integral part of this Agreement.

## 2. Description of Services

2.1 The Customer receives a non-exclusive, revocable, and non-transferable right of use to the platform.

2.2 The Customer is responsible for the implementation (via self-onboarding), unless otherwise specified in the Order Form.

2.3 The Customer agrees to Square8's Fair Use Policy.

## 3. Customer Obligations

3.1 Access to the platform may not be granted to unauthorized third parties.

3.2 The Customer is responsible for all actions of its users and affiliated companies.

3.3 The Customer ensures correct internal processes and master data.

3.4 The platform may not be copied, modified, or reverse engineered.

3.5 The Customer must protect its access credentials and inform Square8 immediately in case of misuse.

3.6 The Customer is obliged to ensure respectful conduct towards Square8 personnel.

## 4. Fees and Payment

4.1 The Customer shall pay the agreed fees in accordance with the Order Form, which sets out all payment specifications, including invoicing, payment terms, taxes, and any price adjustments.

## 5. Warranty and Liability

5.1 Square8 ensures appropriate technical and organizational measures.

5.2 A 98% availability per quarter is guaranteed.

5.3 No warranty is given for error-free or uninterrupted operation.

5.4 No guarantee is given that an AI Worker fully replaces a human employee's judgment on matters requiring human discretion; sensitive steps remain subject to the Customer's configured human sign-off gates.

5.5 Square8 shall only be liable in cases of intent or gross negligence, up to a maximum of the license fees paid in the last quarter.

## 6. Data Protection

6.1 The Customer grants Square8 the right to process data within the scope of providing the services.

6.2 Where the Customer integrates, or grants an AI Worker access to, third-party systems, tools, platforms, or data sources not provided by Square8, the Customer is solely responsible for such third-party systems and for ensuring it holds all rights, licenses, and authorizations necessary to grant such access. Square8 assumes no liability for the availability, security, functionality, or legal compliance of such third-party systems, nor for any actions taken by an AI Worker within them, and disclaims responsibility for any resulting damages, data loss, or third-party claims arising from such integrations or access grants.

## 7. Confidentiality

7.1 Both parties undertake to maintain confidentiality.

7.2 Confidential information must be deleted or returned upon termination of the contract.

## 8. Intellectual Property Rights

8.1 All intellectual property rights in the platform remain with Square8.

8.2 The Customer shall immediately inform Square8 of any third-party claims.

## 9. Customer Output

9.1 All content, deliverables, work results, and other output generated by the AI Worker(s) specifically for the Customer in the course of performing the Services under this Agreement ("Customer Output") shall be the exclusive property of the Customer. Square8 hereby assigns to the Customer, to the extent permitted by law, all right, title and interest — including all intellectual property rights — in and to the Customer Output.

9.2 For the avoidance of doubt, this assignment does not extend to Square8's underlying platform, software, models, tools, templates, methodologies, or any pre-existing or generic intellectual property used to generate the Customer Output ("Square8 IP"), which shall remain the exclusive property of Square8. Square8 IP is licensed to the Customer solely as set out in the SaaS Agreement.

9.3 Customer Output containing Customer data shall be stored and processed exclusively as specified in the SaaS Agreement, and shall be deleted or returned to the Customer in accordance with Section 6 (Data Protection) upon termination of this Agreement.

## 10. Term and Termination

10.1 The term, renewal, and termination of this Agreement are set out in the Order Form.

## 11. Support and Availability

11.1 Support requests can be submitted via the integrated support chat (for admin users) or directly via the contact address support@square8.ai.

11.2 Support levels and response times are structured as follows.

| Severity Level | Description |
| --- | --- |
| Level 1 | The entire Square8 system is unavailable |
| Level 2 | Important functions of Square8 are not working |
| Level 3 | The customer reports an incident not covered by Levels 1 or 2 |

Initial Response times

| Severity Level | Response time |
| --- | --- |
| Level 1 | 8 hours during business hours (1 business day) |
| Level 2 | 16 hours during business hours (2 business days) |
| Level 3 | 24 hours during business hours (3 business days) |

Resolution times

| Severity Level | Resolution times |
| --- | --- |
| Level 1 | 16 hours during business hours (2 business days) |
| Level 2 | 24 hours during business hours (3 business days) |
| Level 3 | 32 hours during business hours (4 business days) |

11.3 Credits may be granted if availability falls below the agreed level.

## 12. Final Provisions

12.1 Force majeure releases the affected party from its obligations.

12.2 Official communication shall be made in text form to the address specified in the Order Form for the Customer and to legal@square8.ai for Square8.

12.3 The Customer may not transfer rights or obligations without consent.

12.4 Amendments are only valid in written form.

12.5 The severability clause applies.

12.6 The courts of Zurich, Switzerland — the registered place of business of Square8 Technologies AG — shall have exclusive jurisdiction.

12.7 This agreement replaces all previous agreements.

12.8 Participation in beta programs is voluntary.

12.9 The Customer may not bind or represent Square8.

12.10 The annexes to this SaaS Agreement form an integral part of the contract.

---

# Annex A — Fair Use Policy

This Fair Use Policy governs the appropriate use of the software-as-a-service services ("Services") provided by Square8 Technologies AG (hereinafter "Square8"). It is intended to protect the integrity, security, and availability of the Services and to ensure fair usage by all customers.

## Permitted Use

The Customer is entitled to use the Services exclusively for lawful and security-related purposes. Permitted uses include in particular:

- granting AI Workers access to the systems, tools, and data of the Customer, or of entities for which the Customer is legally authorized to grant such access,
- configuring AI Workers to perform the tasks and responsibilities defined for their assigned role within the granted scope of access,
- using the audit trail, reporting, and human sign-off features to review and approve AI Worker actions.

## Prohibited Use

The Customer is prohibited from using the Services in particular:

- in violation of applicable laws, regulatory orders, or the rights of third parties,
- on systems, networks, or data belonging to third parties without appropriate authorization,
- to intentionally damage, disrupt, or overload IT systems or networks,
- to distribute malware or malicious code,
- in any manner that could impair the security, stability, or availability of the Square8 platform,
- to engage in Prompt Injection, or to otherwise embed, transmit, or introduce hidden, disguised, or adversarial instructions into content, data, or third-party sources processed by the Services with the intent to manipulate, override, or bypass the AI Worker's intended behavior or security controls.

## Fair Use and Resource Consumption

The use of the Services is subject to the principle of fair and proportionate use. This includes in particular:

- a reasonable number of tasks and system integrations per AI Worker, relative to the subscribed service scope,
- a reasonable volume of AI Worker actions and tool/API calls per AI Worker, relative to the subscribed service scope,
- refraining from automated or mass usage of the platform outside the AI Worker's intended role and purpose.

For the avoidance of doubt, what constitutes a "reasonable" number or volume under this section is assessed per AI Worker and reflects the scope of an individual human role that the AI Worker replaces, and not an entire human team or department. The number of AI Workers made available to the Customer is defined in the Order Form.

Square8 is entitled to define usage-based benchmarks or limits depending on the subscription, product, or individual agreement.

## Monitoring and Measures

Square8 is entitled to monitor the use of the Services to a reasonable extent in order to ensure compliance with this Fair Use Policy. In the event of violations or reasonable suspicion of misuse, Square8 may:

- inform the Customer and request an adjustment of usage,
- temporarily restrict certain functions,
- suspend or terminate access to the Services in whole or in part in the case of serious or repeated violations.

## Responsibility of the Customer

The Customer is responsible for ensuring that:

- it holds all necessary rights and authorizations required to use the Services,
- internal and legally required approvals (e.g., IT approvals, data protection approvals, labor-law related participation requirements) have been obtained,
- affected employees have been informed to the extent required by applicable law.

## Changes to the Fair Use Policy

Square8 reserves the right to amend this Fair Use Policy if necessary for legal, technical, or operational reasons. Changes will be communicated to the Customer in an appropriate manner and shall be deemed accepted if the Customer continues to use the Services after the changes come into effect.

---

# Annex B — Data Processing Addendum (DPA)

## Definitions and Interpretation

Unless otherwise defined herein, the following terms used in this Data Processing Addendum ("DPA") shall have the following meaning:

"Data Protection Laws" means the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection ("FADP"), each as applicable.

"EEA" means the European Economic Area (EU Member States, Liechtenstein, Iceland, and Norway).

"Personal Data Breach" has the meaning given to it under the GDPR, the UK GDPR, or the FADP (data security breach), as applicable.

"Sub-Processor" means any third party engaged by or on behalf of Square8 to process the Customer's personal data in connection with the Agreement.

Otherwise, Article 4 No. 1 GDPR applies; in particular, the terms "Controller", "Processor", "Data Subject", and "Processing" shall be interpreted in accordance with the GDPR, the UK GDPR, and the FADP, as applicable.

## Scope and Provisions

This DPA between Square8 and the Customer, each as defined in the SaaS Agreement, concerns the processing of personal data by Square8 pursuant to Article 28(3) GDPR, Article 28(3) UK GDPR, or Article 9(1) FADP, as applicable, in connection with the Agreement pursuant to Section 1.1 of the SaaS Agreement.

The Customer is the Controller within the meaning of Article 4(7) GDPR, Article 4(7) UK GDPR, and Article 5(j) FADP.

Square8 is the Processor within the meaning of Article 4(8) GDPR, Article 4(8) UK GDPR, and Article 5(k) FADP.

Under the Agreement, the Customer engages Square8 as Processor within the meaning of Article 4(8) GDPR, Article 4(8) UK GDPR, and Article 5(k) FADP.

Both parties acknowledge their obligations under the Data Protection Laws and agree to comply with them.

## Processing of Personal Data

Square8 undertakes to:

- comply with the GDPR, UK GDPR, and FADP, as applicable, in relation to the processing of the Customer's personal data;
- process the Customer's personal data solely for the purpose of fulfilling the Agreement, in particular for providing, operating, and optimizing the platform, services, and implementation as well as maintaining the customer relationship with Square8, and only in accordance with the Customer's documented instructions;
- use artificial intelligence (AI) to perform the tasks assigned to each AI Worker's role. AI Workers act only within the access rights, guardrails, and human sign-off gates configured by the Customer, and any AI-assisted action on a sensitive matter remains subject to the Customer's configured approval requirements.

The Customer:

- has the right at any time to issue instructions regarding the processing of personal data by Square8. Instructions must be given in writing; an email to Square8's Data Protection Officer or privacy contact (dpo@square8.ai) is sufficient. If Square8 believes that an instruction violates applicable data protection laws, Square8 shall inform the Customer without undue delay and may suspend implementation of the instruction until it is confirmed or modified by the Customer.

For clarification: if Square8 is required by applicable law to process the Customer's personal data and such obligation conflicts with the Customer's instructions, Square8 shall inform the Customer where permitted by law.

The Customer is responsible for ensuring that the personal data processed by Square8 has been collected, processed, and transmitted in compliance with applicable data protection laws.

The purpose of the processing is the provision of the services defined in the Agreement, including implementation by Square8 or a partner, the subsequent operation of the platform for and by the Customer, and the provision of further services agreed in the Order Form.

The duration of processing corresponds to the duration of the services provided under the Agreement, including potential storage for archiving purposes upon the Customer's request.

The categories of personal data processed depend on the specific contractual relationship and the Square8 products/modules used by the Customer.

These categories are listed in Annex C of the SaaS Agreement.

The categories of data subjects include employees of the Customer or authorized entities of the Customer.

Processing activities by Square8 include all activities necessary to perform the Agreement and manage the customer relationship, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, alignment, restriction, deletion, or destruction.

Square8 implements appropriate measures to ensure the reliability of personnel with access to personal data, including screening procedures and regular training, including annual security awareness training.

All Square8 employees sign confidentiality agreements.

Where required by applicable law, Square8 appoints an internal Data Protection Officer or privacy contact, reachable at **dpo@square8.ai**.

## Security

Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as risks of varying likelihood and severity, Square8 has implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

These measures include those referred to in Article 32 GDPR, Article 32 UK GDPR, and Article 8 FADP.

Details are described in the Technical and Organizational Measures (TOMs) in Annex E.

## Sub-Processors

The Customer expressly agrees to the Sub-Processors listed in Annex D.

Square8 will notify the Customer at least two weeks before engaging new or replacement Sub-Processors.

If no objection is raised within this period, the Sub-Processor is deemed approved.

Square8 has concluded data processing agreements with all Sub-Processors in accordance with Article 28 GDPR and equivalent provisions.

These agreements ensure that Sub-Processors comply with the same high standards of data protection.

## Partners

Square8 works with partners to distribute and implement the platform and integrate third-party services.

Square8 may share Customer data with partners where required for the requested partner service, strictly on a need-to-know basis and under confidentiality obligations.

## Personal Data Breaches / Data Subject Requests

Square8 shall notify the Customer without undue delay after becoming aware of a personal data breach and provide sufficient information to enable the Customer to comply with its reporting obligations.

Square8 will assist the Customer in investigating and mitigating the breach and in responding to data subject requests under applicable data protection laws.

## Data Protection Impact Assessments

Square8 will reasonably assist the Customer with data protection impact assessments and consultations with supervisory authorities where required.

## Deletion or Return of Personal Data

Upon termination of the Services, Square8 shall, at the Customer's choice:

- delete all copies of the Customer's personal data within 30 days, or
- return the personal data to the Customer and subsequently delete all copies.

Square8 may retain personal data if legally required or if the Customer instructs Square8 to archive it in a secure archive.

## Audit Rights

Upon request, Square8 will provide information necessary to demonstrate compliance with this DPA.

## Data Transfers

Where personal data is transferred outside the EU/EEA, Square8 ensures appropriate safeguards through:

- adequacy decisions by the EU Commission, UK authorities, or the Swiss Federal Council,
- Standard Contractual Clauses approved under GDPR, UK law, or Swiss law,
- Binding Corporate Rules where applicable.

Square8 monitors the EU-US Data Privacy Framework certification list and may rely on certified providers.

---

# Annex C — Categories of Processed Data

Depending on the Square8 products/modules included in the Agreement, the following categories of data may be processed.

**Square8 Platform**

- Company name
- Company domain(s)
- Public or non-public corporate email addresses
- Employee first and last name
- Business email address
- Job title, role, department, or team
- Profile photo/picture (where provided)
- Organizational structure data (e.g. reporting lines, team or role assignments)
- Content uploaded by the Customer into Square8 that may contain personal data
- Communications data, including requests submitted to and responses generated by an AI Worker (e.g. chat, ticket, task, or email content)
- Data accessed by an AI Worker within the systems and tools granted by the Customer (e.g. HRIS, CRM, ticketing, finance, or communication systems), as configured for the AI Worker's role
- Where configured by the Customer, personal data of the Customer's own customers or other third parties processed by an AI Worker in the course of performing its assigned tasks (e.g. support tickets, CRM records)

---

# Annex D — Sub-Processors

- **Google Cloud Platform (GCP)**, contracted via Google Cloud EMEA Limited (70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland) — Cloud Service Provider. EU-based hosting only, using regions europe-west1 (Belgium), europe-west2 (London), europe-west3 (Frankfurt), europe-west4 (Netherlands), europe-west6 (Zurich), europe-west8 (Milan), europe-west9 (Paris), europe-west10 (Berlin), europe-west12 (Turin), and europe-central2 (Warsaw). Transfers, where applicable, are governed by the Google Cloud Data Processing Addendum incorporating the EU Standard Contractual Clauses.
- **Amazon Web Services (AWS)**, contracted via Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg) — Cloud Service Provider. EU-based hosting only, using regions eu-west-1 (Ireland), eu-west-2 (London), eu-west-3 (Paris), eu-central-1 (Frankfurt), and eu-central-2 (Zurich). Transfers, where applicable, are governed by the AWS GDPR Data Processing Addendum incorporating the EU Standard Contractual Clauses.
- **Mailgun** (Mailgun Technologies, Inc., a Sinch company; 112 E Pecan St. #1135, San Antonio, TX 78205, USA) — Notification services (transactional email). Certified under the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as a fallback transfer mechanism.
- **Anthropic** (Anthropic PBC; 548 Market Street, PMB 90375, San Francisco, CA 94104, USA) — AI model operation. Transfers safeguarded via Standard Contractual Clauses (Art. 46 GDPR).
- **OpenAI** (OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland — contracting entity for EEA/Swiss customers) — AI model operation. Transfers safeguarded via Standard Contractual Clauses or an applicable EU adequacy decision.
- **Perplexity** (Perplexity AI, Inc.; 115 Sansome St, Suite 900, San Francisco, CA 94104, USA) — AI model operation. Transfers safeguarded via Standard Contractual Clauses under Perplexity's Data Processing Addendum; EU representative: Prighter Group, Vienna, Austria.
- **Cloudflare** (Cloudflare, Inc.; 701 Townsend St., San Francisco, CA 94107, USA) — CDN and network security services. Transfers safeguarded via Standard Contractual Clauses under Cloudflare's Data Processing Addendum.
- **Customer.io** (Peaberry Software Inc. d/b/a Customer.io; 9450 SW Gemini Dr., Suite 43920, Beaverton, OR 97008, USA) — Notification services (customer engagement/email). Transfers safeguarded via Standard Contractual Clauses under Customer.io's Data Processing Addendum.
- **HubSpot** (HubSpot Ireland Limited, HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, Ireland — contracting entity for EU/UK customers) — CRM and customer support tooling. Transfers safeguarded via the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
- **Hetzner Online GmbH** (Industriestr. 25, 91710 Gunzenhausen, Germany) — Cloud Service Provider. EU-based hosting, using Hetzner's data centers in Germany and Finland.

The list of Sub-Processors may be updated from time to time. The current list is available online at **square8.ai/saas-agreement**.

---

# Annex E — Technical and Organizational Measures (TOMs)

## Introduction

This document describes the technical and organizational measures implemented by Square8 to protect data against unauthorized access, misuse, accidental deletion, and loss.

Square8 operates an AI workforce platform designed to ensure a high level of security throughout the information processing lifecycle.

Square8 maintains an information security program aligned with recognized industry security practices, including controls modeled on the ISO 27001 framework. Square8's information security program is designed to meet ISO 27001 requirements.

## Scope

The technical and organizational measures described pursuant to Article 32 GDPR, Article 32 UK GDPR, and Article 8 FADP apply to all Square8 entities.

## Data Protection and Security Concept

Square8 manages its security measures based on the **Parkerian Hexad model**, which expands the classical CIA triad (confidentiality, integrity, availability) with three additional elements:

- possession/control
- authenticity
- utility (usability)

This holistic approach ensures comprehensive protection of customer data.

## Security Attributes

**Confidentiality** — Protection of data against unauthorized access or disclosure.

**Integrity** — Accuracy and completeness of information during processing.

**Availability** — Ensuring systems and information are accessible when needed.

**Possession/Control** — Ensuring only authorized persons control systems and data.

**Authenticity** — Ensuring data originates from the stated source.

**Usability** — Ensuring information remains usable and understandable.

## Confidentiality Measures

Measures include physical access control, system access control, encryption, role-based access control, and strict employee access policies.

Square8 hosts its infrastructure on third-party data centers, which include strict physical security controls such as:

- security personnel
- biometric authentication
- access badges
- surveillance systems.

Employees receive security training and sign confidentiality agreements.

## Integrity

**Transmission Control**

All data is encrypted during transmission using **industry-standard encryption (TLS)**.

**Input Control**

Processes ensure correctness, completeness, and consistency of entered data.

## Availability and Reliability

Square8 operates a **scalable, cloud-based backend architecture**.

Databases are backed up on a regular basis and stored in encrypted cloud storage.

Square8 maintains **business continuity procedures**.

## Monitoring and Evaluation

Square8 maintains a privacy framework and internal processes to continuously monitor and improve data protection practices.

## Data Protection Management

Where required by applicable law, Square8 appoints an internal **Data Protection Officer**.

Customers conclude a **Data Processing Addendum** as part of the SaaS Agreement.

Where required, **data transfer impact assessments** are performed as needed.

## Incident Response Management

Square8 maintains defined procedures and reporting channels for responding to security incidents and continuously improving processes.

## Instruction Control

Personal data is processed only according to the Customer's instructions as defined in the DPA.

## Privacy by Design and by Default

**Privacy by Design**

Personal data is collected only where necessary and categories are transparently listed in Annex C.

**Privacy by Default**

Default settings ensure personal data is processed only for defined purposes.

Employees are trained and bound by confidentiality agreements.

---

# Annex F — EU AI Act: Roles and Responsibilities

**Purpose**

This Annex F addresses the allocation of responsibilities between Square8 and the Customer under Regulation (EU) 2024/1689 (the "EU AI Act"), to the extent applicable to the Customer's use of the Platform and AI Workers. It supplements, and does not replace, either Party's own legal obligations under the EU AI Act or any equivalent national implementing legislation.

**Roles under the EU AI Act**

The Platform integrates general-purpose AI (GPAI) models operated by third-party model providers listed in Annex D (including Anthropic, OpenAI, and Perplexity), each of which acts as a GPAI model provider under Articles 53 and, where applicable, 55 of the EU AI Act and is independently responsible for its own transparency, technical documentation, and safety obligations.

Depending on the specific configuration, Square8 generally acts as the provider of an AI system within the meaning of the EU AI Act with respect to the Platform, while the Customer generally acts as a deployer within the meaning of the EU AI Act with respect to its use of AI Workers within its organization. Where the Customer configures, fine-tunes, or substantially modifies the intended purpose of an AI Worker, the Customer may itself be treated as a provider for that specific configuration under Article 25 of the EU AI Act. The Parties shall cooperate in good faith to clarify role allocation in such cases.

**Risk Classification and Deployer Obligations**

The Customer is solely responsible for assessing whether its specific use case(s) for an AI Worker fall within a high-risk category under Annex III of the EU AI Act (for example, use in employment or worker management) and for implementing the corresponding deployer obligations, including human oversight, fundamental rights impact assessments where required, record-keeping, and registration obligations. Square8 will provide reasonable technical documentation and support to enable the Customer to comply with such obligations upon request.

**Human Oversight**

The Platform is designed to support human oversight through configurable human sign-off gates, audit trails, and reporting features described elsewhere in this SaaS Agreement and its Annexes. The Customer remains responsible for configuring and maintaining these controls appropriately for its use case, in particular for any sensitive or high-risk decisions.

**Transparency (Article 50)**

Where an AI Worker interacts directly with natural persons, the Customer is responsible for ensuring that such persons are informed that they are interacting with an AI system, in accordance with Article 50(1) of the EU AI Act, unless this is obvious from the circumstances. Square8 will provide reasonable technical support to enable such disclosures within the Platform.

**AI Literacy (Article 4)**

Each Party shall take reasonable measures to ensure a sufficient level of AI literacy among its own personnel and other persons operating or using the Services on its behalf, in accordance with Article 4 of the EU AI Act.

**Cooperation and Updates**

The Parties will cooperate in good faith and provide reasonably requested information to support each other's compliance with the EU AI Act. Square8 will update this Annex F as its own obligations and the applicable regulatory timeline evolve, including as further implementing guidance, delegated acts, or legislative amendments (including under the European Commission's "Digital Omnibus" simplification package) become applicable.

---

# Annex G — Test Customers Without an Order Form

This Annex G governs any access to or use of the Platform or Services by a Customer that has not signed an Order Form, including access granted for trial, demo, proof-of-concept, sandbox, or other evaluation purposes (a "Test Customer"). In the event of any conflict between this Annex G and any other provision of the SaaS Agreement or its other Annexes, this Annex G prevails with respect to Test Customers.

## Scope and Precedence

This Annex G applies exclusively to Test Customers. A Customer ceases to be a Test Customer, and this Annex G ceases to apply, from the moment an Order Form is validly signed between the Parties. From that moment, the SaaS Agreement and its Annexes A–F apply in full, without retroactive effect for the period during which the Customer was a Test Customer.

## Nature of Access

Access to the Platform or Services by a Test Customer is granted, if at all, on a purely gratuitous, non-exclusive, revocable, and discretionary basis. Square8 is under no obligation to grant, continue, or renew such access, and may condition, suspend, restrict, or terminate it at any time, with or without notice, with or without cause, and without any liability to the Test Customer.

## No Rights Under the SaaS Agreement or Annexes

Except as expressly stated in this Annex G, a Test Customer does not acquire, and Square8 does not grant, any of the rights, entitlements, or protections set out in the SaaS Agreement or Annexes A–F, including without limitation:

- any service levels, uptime commitments, or support obligations;
- any warranty of any kind, express or implied, including as to availability, accuracy, fitness for a particular purpose, or non-infringement;
- any right to data portability, data export, data retention, or backup;
- any indemnity from Square8;
- any right to notice, cure periods, or a minimum term prior to suspension or termination;
- any license or other right in Square8's Intellectual Property Rights beyond the bare, revocable permission to access the Platform for evaluation purposes described in this Annex G;
- any right to rely on the Fair Use Policy (Annex A) as a benchmark of permitted usage — usage limits for Test Customers are set solely at Square8's discretion and may be withdrawn at any time;
- any protections under the Data Processing Addendum (Annex B), the Categories of Processed Data (Annex C), the Sub-Processor list (Annex D), or the Technical and Organizational Measures (Annex E), other than the minimum obligations Square8 owes as a matter of mandatory data protection law where it processes Personal Data on the Test Customer's behalf;
- any allocation of roles or responsibilities under Annex F (EU AI Act), other than those mandatorily imposed by applicable law.

For the avoidance of doubt, the absence of a right under this Annex G does not diminish any obligation the Test Customer owes to Square8 under the SaaS Agreement, this Annex G, or applicable law, including the obligations on lawful and permitted use, confidentiality, and Intellectual Property Rights, all of which continue to bind the Test Customer in full.

## No Fees; No Commercial Terms

Unless otherwise agreed in writing, a Test Customer owes no Fees for access under this Annex G, and Square8 makes no commitment as to the pricing, availability, or terms on which a subsequent Order Form might be offered.

## Data

The Test Customer acknowledges that the Platform is not configured, and Square8 is not obligated, to provide the safeguards set out in Annex B, C, D, or E for a Test Customer. The Test Customer must not submit Personal Data, Confidential Information of third parties, or production data of any kind to the Platform under this Annex G. Where the Test Customer nonetheless submits Personal Data, Square8's obligations are limited to those mandatorily imposed by applicable data protection law (including the GDPR and the Swiss DSG, as applicable); no additional contractual assurance is given under this Annex G.

## Confidentiality and Intellectual Property

The Test Customer must treat all non-public information about the Platform, including its functionality, performance, and any output obtained during testing, as Confidential Information of Square8, and must not disclose it to any third party or use it other than for the sole purpose of evaluating the Services. All Intellectual Property Rights in the Platform and Services remain vested exclusively in Square8; nothing in this Annex G or in the Test Customer's use of the Platform transfers or licenses any such rights beyond the bare right of access described above.

## Liability

To the maximum extent permitted by applicable law, Square8's aggregate liability towards a Test Customer arising out of or in connection with access under this Annex G is excluded, regardless of the legal theory on which it is based. This exclusion does not apply to liability for wilful misconduct or gross negligence, or to any other liability that cannot be excluded or limited under mandatory applicable law (including Art. 100 of the Swiss Code of Obligations).

## Termination

Square8 may suspend or terminate a Test Customer's access under this Annex G at any time, immediately and without notice. The Test Customer may discontinue use at any time. Upon termination, Square8 may delete any Customer Data submitted by the Test Customer without further notice and without any obligation to retain, return, or export it.

## Entire Agreement for Test Customers

For a Test Customer, this Annex G, together with the definitions in Section 1 of the SaaS Agreement to the extent referenced herein, constitutes the entire agreement between the Parties regarding the Test Customer's access to the Platform, and supersedes any prior or contemporaneous understanding on the subject. No other provision of the SaaS Agreement or its Annexes A–F applies to a Test Customer unless this Annex G expressly says so.
