DATA PROCESSING AGREEMENT

Version: August 2026

TEQQ ApS · CVR 43013629 · Denmark

This Data Processing Agreement (the “DPA”) forms part of the agreement, order, offer, statement of work or other commercial arrangement (the “Agreement”) between TEQQ ApS, CVR no. 43013629, Denmark (“TEQQ” or the “Processor”), and the customer identified in the applicable Agreement (the “Customer” or the “Controller”).

The Customer and TEQQ are individually a “Party” and collectively the “Parties”.

1. PURPOSE AND SCOPE

1.1 This DPA applies where and to the extent that TEQQ processes Personal Data on behalf of the Customer in connection with services provided under the Agreement.

1.2 Such processing may arise in connection with, among other things: collection and transportation of IT equipment; receipt, registration and secure storage of IT equipment; inspection and testing of equipment; data sanitisation and data erasure; physical destruction of data-bearing media; refurbishment and preparation of equipment for reuse; preparation of data erasure, destruction, chain-of-custody or related documentation; and other agreed IT asset lifecycle services.

1.3 This DPA does not by itself establish that TEQQ acts as a Processor in respect of every activity performed under the Agreement. The Parties' respective roles shall be determined by the actual processing activity and applicable Data Protection Law.

1.4 Where TEQQ processes Personal Data for its own legitimate and independent purposes, including ordinary business administration, invoicing, legal compliance and management of its commercial relationship with the Customer, TEQQ acts as an independent controller in respect of such processing and such processing is outside the scope of this DPA.

2. DEFINITIONS

For the purposes of this DPA:

“Data Protection Law” means Regulation (EU) 2016/679 (the “GDPR”) and any applicable national legislation supplementing or implementing the GDPR.

“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” shall have the meanings given to them in the GDPR.

“Customer Equipment” means any IT equipment, storage media or other assets entrusted to TEQQ in connection with the Services.

“Services” means the services supplied by TEQQ under the applicable Agreement.

“Sub-processor” means another processor engaged by TEQQ to process Personal Data on behalf of the Customer.

3. CUSTOMER RESPONSIBILITIES AND INSTRUCTIONS

3.1 The Customer is responsible for ensuring that: (a) its Processing of Personal Data complies with applicable Data Protection Law; (b) it has an appropriate lawful basis for the Processing and for engaging TEQQ to perform the Services; (c) all instructions provided to TEQQ comply with applicable law; (d) Personal Data contained on Customer Equipment has been collected and processed lawfully; and (e) it provides TEQQ with sufficient information and instructions to enable TEQQ to perform its obligations under this DPA.

3.2 TEQQ shall process Personal Data only on documented instructions from the Customer, including as necessary to perform the Services under the Agreement, unless Processing is required by applicable EU or Member State law.

3.3 Where TEQQ is required by law to process Personal Data otherwise than in accordance with the Customer's instructions, TEQQ shall inform the Customer of that legal requirement before Processing, unless prohibited from doing so by law.

3.4 TEQQ shall promptly inform the Customer if, in TEQQ's reasonable opinion, an instruction infringes applicable Data Protection Law.

3.5 TEQQ may suspend execution of an instruction that it reasonably considers unlawful until the Customer confirms, modifies or withdraws the instruction.

4. PERSONAL DATA CONTAINED ON CUSTOMER EQUIPMENT

4.1 The Customer acknowledges that Customer Equipment may contain Personal Data when transferred into TEQQ's custody.

4.2 TEQQ does not require access to the content of Personal Data stored on Customer Equipment for its own purposes and shall not intentionally inspect, use, copy, disclose or otherwise process such content except: (a) to the extent necessary to perform the agreed Services; (b) where technically unavoidable in performing the Services; (c) pursuant to documented instructions from the Customer; or (d) where required by applicable law.

4.3 TEQQ shall, where reasonably practicable, perform data sanitisation or destruction without reviewing the underlying content stored on the relevant media.

4.4 Unless specifically agreed otherwise, TEQQ shall not create copies or backups of Personal Data contained on Customer Equipment.

4.5 Where data-bearing media cannot be successfully sanitised in accordance with the agreed method, TEQQ may, where agreed or reasonably necessary to achieve secure disposition, physically destroy the relevant media and document such destruction.

5. CONFIDENTIALITY AND AUTHORISED PERSONNEL

5.1 TEQQ shall ensure that persons authorised to process Personal Data: (a) process Personal Data only as necessary for the performance of their duties; (b) are subject to appropriate confidentiality obligations; and (c) receive appropriate security and operational instructions relevant to their responsibilities.

5.2 Access to Customer Equipment and Personal Data shall be limited to personnel and authorised parties requiring such access for performance of the Services.

5.3 The confidentiality obligations under this Section shall continue after termination or expiry of the Agreement.

6. SECURITY OF PROCESSING

6.1 Taking into account the state of the art, costs of implementation, nature, scope, context and purposes of Processing and the risks to the rights and freedoms of natural persons, TEQQ shall implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR.

6.2 Such measures may include, as appropriate: physical access controls; controlled access to facilities and processing areas; personnel access restrictions; confidentiality obligations; secure storage of Customer Equipment; asset registration and tracking; chain-of-custody procedures; controlled data sanitisation and destruction processes; incident management procedures; appropriate information-security policies and procedures; and measures designed to maintain the confidentiality, integrity and availability of systems and services relevant to the Processing.

6.3 The technical and organisational measures applicable to the Processing are further described in Annex 2.

6.4 TEQQ may modify its technical and organisational measures from time to time, provided that such modifications do not materially reduce the overall level of security applicable to the Services.

7. SUB-PROCESSORS

7.1 The Customer grants TEQQ general authorisation to engage Sub-processors where reasonably necessary for provision of the Services.

7.2 TEQQ shall ensure that any Sub-processor that processes Personal Data on behalf of the Customer is bound by data protection obligations providing an appropriate level of protection consistent with the requirements applicable to TEQQ under this DPA.

7.3 TEQQ shall remain responsible for the performance of its Sub-processors' data protection obligations to the extent required under Article 28 GDPR.

7.4 TEQQ may add or replace Sub-processors. Where such change is material to the Processing of Personal Data, TEQQ shall provide reasonable notice to the Customer where required under applicable Data Protection Law.

7.5 The Customer may object to a new Sub-processor on reasonable and documented data protection grounds. The Parties shall cooperate in good faith to identify a commercially reasonable solution.

7.6 Providers performing ordinary transportation or logistics services shall not automatically be considered Sub-processors solely because they transport Customer Equipment. Their role shall be determined based on the nature of their activities and their actual access to or Processing of Personal Data.

8. INTERNATIONAL TRANSFERS

8.1 TEQQ shall not transfer Personal Data subject to this DPA to a country outside the European Economic Area unless such transfer complies with Chapter V of the GDPR.

8.2 Where required, TEQQ shall implement an appropriate transfer mechanism, which may include: (a) an adequacy decision adopted by the European Commission; (b) applicable Standard Contractual Clauses adopted by the European Commission; or (c) another legally recognised transfer mechanism.

8.3 For clarity, transportation of Customer Equipment shall not constitute an international transfer of Personal Data by TEQQ where the circumstances do not constitute a transfer under applicable Data Protection Law.

9. ASSISTANCE TO THE CUSTOMER

9.1 Taking into account the nature of the Processing, TEQQ shall provide reasonable assistance to the Customer, insofar as reasonably possible, in responding to requests from Data Subjects exercising their rights under Chapter III GDPR.

9.2 TEQQ shall not respond directly to a Data Subject request concerning Personal Data processed on behalf of the Customer unless instructed by the Customer or required by applicable law.

9.3 Taking into account the nature of the Processing and the information available to TEQQ, TEQQ shall provide reasonable assistance to the Customer in ensuring compliance with the Customer's obligations under Articles 32–36 GDPR, including where applicable: security of Processing; notification of Personal Data Breaches; communication of Personal Data Breaches to Data Subjects; data protection impact assessments; and prior consultation with a Supervisory Authority.

9.4 Unless such assistance is required as a direct consequence of TEQQ's breach of this DPA, TEQQ may charge its reasonable costs for material assistance exceeding the ordinary scope of the Services.

10. PERSONAL DATA BREACHES

10.1 TEQQ shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed by TEQQ on behalf of the Customer.

10.2 To the extent reasonably available, the notification shall contain information necessary to assist the Customer in complying with its obligations under Article 33 GDPR, including: (a) the nature of the Personal Data Breach; (b) where reasonably possible, the categories of affected Data Subjects and Personal Data; (c) the likely consequences of the Personal Data Breach; and (d) measures taken or proposed to address or mitigate the Personal Data Breach.

10.3 Where information is not available at the time of the initial notification, TEQQ may provide such information in phases without undue further delay.

10.4 TEQQ shall take reasonable measures to contain, investigate and mitigate a Personal Data Breach within its control.

10.5 Notification of a Personal Data Breach shall not constitute an acknowledgement of fault or liability by TEQQ.

11. RETURN AND DELETION OF PERSONAL DATA

11.1 Customer Equipment may contain Personal Data until the agreed data sanitisation or destruction process has been successfully completed.

11.2 Upon successful completion of the applicable sanitisation or destruction process, TEQQ shall have no obligation to preserve or recover Personal Data previously contained on the relevant Customer Equipment.

11.3 Upon termination or expiry of the Services involving Processing, TEQQ shall, at the Customer's choice and where applicable, delete or return Personal Data processed on behalf of the Customer, unless applicable law requires continued storage.

11.4 Section 11.3 shall not require TEQQ to return Personal Data that existed solely on media which, pursuant to the Services and the Customer's instructions, has been securely erased or physically destroyed.

11.5 TEQQ may retain ordinary business records, transaction records, asset information, erasure certificates, destruction certificates, audit records and other documentation that does not contain the underlying Personal Data stored on Customer Equipment, where required or reasonably necessary for legal, contractual, audit, security or compliance purposes.

12. INFORMATION AND AUDIT RIGHTS

12.1 TEQQ shall make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

12.2 The Parties shall, where reasonably possible, use existing certifications, audit reports, security documentation, policies or other documentary evidence to demonstrate compliance before requiring an on-site audit.

12.3 Where the Customer reasonably requires an additional audit, TEQQ shall permit and reasonably contribute to such audit, including inspections where required by Article 28 GDPR.

12.4 Except where a shorter period is reasonably required due to a Personal Data Breach, regulatory requirement or reasonable evidence of material non-compliance, audits shall: (a) be subject to reasonable prior written notice; (b) take place during normal business hours; (c) be conducted in a manner that minimises disruption to TEQQ's operations; (d) comply with TEQQ's reasonable security and confidentiality requirements; (e) not provide access to information relating to other customers; and (f) not require disclosure of information that would compromise TEQQ's security or the confidentiality rights of third parties.

12.5 The Customer may appoint an independent auditor provided that the auditor is not a competitor of TEQQ and is subject to appropriate confidentiality obligations.

12.6 Unless an audit identifies a material breach of this DPA attributable to TEQQ or the audit is specifically required by a competent Supervisory Authority, the Customer shall bear its own costs and TEQQ's reasonable costs associated with extraordinary audit assistance.

12.7 Nothing in this Section limits the statutory powers of a competent Supervisory Authority.

13. REGULATORY COOPERATION

13.1 TEQQ shall cooperate with competent Supervisory Authorities to the extent required by applicable Data Protection Law.

13.2 Where legally permitted, TEQQ shall notify the Customer of any binding request from a Supervisory Authority specifically relating to Personal Data processed on behalf of the Customer.

14. LIABILITY

14.1 Each Party remains responsible for its own compliance with applicable Data Protection Law.

14.2 Nothing in this DPA excludes or limits liability to the extent that such exclusion or limitation is prohibited by applicable law.

14.3 Subject to Section 14.2, TEQQ's liability arising from or relating to this DPA shall be subject to the exclusions, limitations and liability cap contained in the Agreement and/or TEQQ's applicable General Terms and Conditions.

14.4 The Customer shall remain responsible for the lawfulness, accuracy and scope of its instructions and for Personal Data placed on or retained within Customer Equipment prior to delivery to TEQQ.

14.5 This DPA does not create any separate payment, purchase, repurchase, valuation or ownership obligation concerning Customer Equipment.

15. TERM AND TERMINATION

15.1 This DPA applies automatically where it is referenced or incorporated into an offer, order confirmation, agreement, statement of work or other contractual document issued or accepted by TEQQ and where TEQQ processes Personal Data on behalf of the Customer in connection with the applicable Services. No separate signature of this DPA is required.

15.2 This DPA remains in force for as long as TEQQ processes Personal Data on behalf of the Customer under the Agreement.

15.3 Termination or expiry of this DPA shall not affect provisions which by their nature are intended to survive, including confidentiality, deletion, audit, liability and applicable legal obligations.

16. ORDER OF PRECEDENCE

16.1 In the event of a conflict between this DPA and the Agreement concerning the Processing of Personal Data, this DPA shall prevail solely with respect to the relevant data protection matter.

16.2 In all other respects, including commercial terms, pricing, warranties, ownership, risk, indemnities and limitations of liability, the Agreement and TEQQ's applicable General Terms and Conditions shall govern.

16.3 Where mandatory Data Protection Law conflicts with this DPA, mandatory Data Protection Law shall prevail to the extent of the conflict.

17. GOVERNING LAW

17.1 This DPA shall be governed by the same governing law and dispute-resolution provisions as the Agreement.

17.2 Where the Agreement does not specify governing law, this DPA shall be governed by Danish law and disputes shall be subject to the competent Danish courts.


 

ANNEX 1 – DETAILS OF PROCESSING

1. Subject matter

Processing of Personal Data that may be contained on or otherwise associated with Customer Equipment entrusted to TEQQ in connection with the Services.

2. Duration

For the period during which TEQQ has custody of, access to or otherwise processes relevant Personal Data on behalf of the Customer, including the period necessary to complete agreed data sanitisation, destruction and associated documentation.

3. Nature and purpose of Processing

Depending on the Services ordered, Processing may include receipt and handling of Customer Equipment; transportation and secure storage; registration and identification of assets; technical testing where required; access technically necessary to perform sanitisation; data sanitisation/data erasure; destruction of data-bearing media; verification and documentation of sanitisation or destruction; and related IT asset lifecycle activities performed on the Customer's documented instructions. The principal purpose is secure handling and disposition of Personal Data contained on Customer Equipment in connection with the agreed Services.

4. Categories of Data Subjects

Personal Data may relate to employees and former employees of the Customer; contractors and consultants; customers and prospective customers; suppliers and business partners; users of Customer IT systems; and other individuals whose Personal Data has been stored on Customer Equipment. TEQQ does not determine which Data Subjects' information is stored on Customer Equipment.

5. Types of Personal Data

Customer Equipment may potentially contain any category of Personal Data stored by the Customer, including identification and contact information; employment-related information; correspondence and documents; account and system information; technical and usage information; financial or commercial information; and other Personal Data processed by the Customer. Depending upon the Customer's use of the equipment, Personal Data may include special categories of Personal Data under Article 9 GDPR or other confidential or sensitive information. TEQQ neither requires nor requests that the Customer provide such information separately from the Customer Equipment.

6. Processing frequency

Processing occurs as required to perform individual orders, projects or ongoing Services under the Agreement.


 

ANNEX 2 – TECHNICAL AND ORGANISATIONAL MEASURES

TEQQ maintains technical and organisational measures appropriate to the nature of its Services and the risks associated with Customer Equipment and Personal Data under its custody. Such measures may include, where relevant to the Services:

Physical security

  • controlled access to facilities.

  • restricted access to areas containing Customer Equipment.

  • appropriate premises security.

  • secure storage arrangements.

  • monitoring or surveillance measures where appropriate.

Personnel security

  • access limited according to operational need.

  • confidentiality obligations.

  • appropriate personnel instruction and training.

  • controlled authorisation to handle Customer Equipment.

Asset handling and chain of custody

  • registration and identification of received equipment where included in the Services.

  • controlled movement of equipment.

  • appropriate chain-of-custody procedures.

  • segregation and secure storage where appropriate.

  • documentation of relevant processing activities.

Data sanitisation and destruction

  • controlled data sanitisation procedures.

  • use of appropriate sanitisation methods and tools according to the agreed service.

  • verification of sanitisation where included in the Services.

  • physical destruction where sanitisation is unsuccessful, inappropriate or destruction has otherwise been agreed.

  • preparation of sanitisation and/or destruction documentation where included in the Services.

Information security

  • access controls appropriate to relevant systems.

  • appropriate authentication and authorisation controls.

  • confidentiality and security procedures.

  • incident-management processes.

  • periodic review of relevant security measures.

Supplier and Sub-processor management

  • appropriate selection and assessment.

  • contractual data protection obligations.

  • confidentiality and security requirements.

  • oversight appropriate to the nature and risk of the services provided.

TEQQ may update these measures in accordance with Section 6.4 of the DPA, provided that the overall level of protection is not materially reduced.