Version 1.0 · In force from 4 August 2026

SCHEDULE I

SUBPROCESSOR GOVERNANCE & APPROVED SUBPROCESSOR REGISTER

(Annex to the Data Processing Agreement) Version 1.0 · Effective Date: 4 August 2026

This Subprocessor Governance & Approved Subprocessor Register (this "Schedule") forms an integral part of the Terms of Service (the "Agreement") accepted electronically by the Customer (including by clickwrap acceptance during account registration or online checkout). This document is published at a permanent URL on ONLYAI’s website and is incorporated into the Agreement by reference. It applies between DOSTART VENTURES LIMITED, registration number HE 487770, registered under the laws of Cyprus ("Company", "Dostart Ventures", "Processor", "Provider", "we", "our" or "us") and the Customer identified in the applicable electronic Order Form ("Customer" or "Controller").

Capitalized terms not otherwise defined herein shall have the meanings assigned to them in the Agreement or the DPA.

1. PURPOSE

1.1 Objective

The Company recognizes that the secure and lawful engagement of third-party service providers constitutes an essential component of its information security, privacy governance and operational resilience framework.

Accordingly, this Schedule establishes the principles governing:

  • the appointment of Subprocessors;
  • the Company's Subprocessor governance framework;
  • minimum contractual safeguards applicable to Subprocessors;
  • Customer notification procedures;
  • Customer objection rights;
  • ongoing monitoring of Subprocessor performance;
  • the Approved Subprocessor Register.

This Schedule has been prepared having regard to Article 28 GDPR, internationally recognized information security principles and enterprise cloud computing best practices.

1.2 Scope

This Schedule applies exclusively to third-party organizations engaged by the Company to Process Customer Data on behalf of Customers in connection with the provision of the ONLYAI Platform.

Nothing contained herein shall prevent the Company from engaging professional advisers, telecommunications providers, financial institutions or other service providers who do not Process Customer Data on behalf of Customers.

2. SUBPROCESSOR GOVERNANCE PRINCIPLES

The Company maintains a risk-based Subprocessor governance programme designed to ensure that Customer Data remains subject to an appropriate level of contractual, organizational and technical protection throughout the processing chain.

The Company seeks to engage only those Subprocessors capable of demonstrating security, confidentiality and operational standards appropriate to the nature of the Processing activities performed.

Appointment of a Subprocessor shall not relieve the Company of any obligations owed to the Customer under the Agreement or the DPA.

2.1 Accountability

The Company remains fully responsible for the performance of its obligations under the DPA notwithstanding the appointment of any Subprocessor.

The Company shall remain liable for the acts and omissions of its Subprocessors to the extent required by Article 28 GDPR and the Agreement.

2.2 Data Minimization

The Company shall seek to ensure that each Subprocessor receives access only to those categories of Customer Data reasonably necessary for the performance of the specific services for which such Subprocessor has been engaged.

2.3 Least Privilege

Where technically and operationally feasible, Customer Data shall be disclosed to Subprocessors on a least-privilege basis consistent with the principle of data minimization.

3. SUBPROCESSOR DUE DILIGENCE

3.1 Vendor Assessment

Prior to appointing a Subprocessor that will Process Customer Data, the Company shall undertake a commercially reasonable assessment of the prospective Subprocessor's suitability.

Such assessment may include consideration of:

  • information security maturity;
  • privacy governance framework;
  • technical capabilities;
  • operational resilience;
  • incident response capabilities;
  • applicable certifications;
  • financial stability;
  • reputation;
  • regulatory compliance history;
  • geographic location of Processing activities.

The scope of such assessment shall be proportionate to the nature and risk of the proposed Processing activities.

3.2 Risk-Based Approach

Subprocessors shall be assessed having regard to:

  • categories of Customer Data Processed;
  • volume of Processing;
  • sensitivity of information;
  • operational criticality;
  • cross-border transfer considerations;
  • reliance on artificial intelligence technologies;
  • cybersecurity exposure.

Higher-risk Processing activities may be subject to enhanced due diligence procedures.

4. CONTRACTUAL SAFEGUARDS

Prior to permitting a Subprocessor to Process Customer Data, the Company shall enter into a written agreement imposing obligations substantially equivalent to those imposed upon the Company under the Data Processing Agreement.

Without limitation, such agreement shall require the Subprocessor to:

  • Process Customer Data solely on documented instructions;
  • maintain appropriate technical and organizational measures;
  • ensure confidentiality of authorized personnel;
  • assist with Data Subject Requests where appropriate;
  • notify the Company without undue delay following discovery of a Personal Data Breach;
  • implement appropriate international transfer safeguards where applicable;
  • return or securely delete Customer Data upon termination of services, unless retention is required by Applicable Law;
  • permit audits or provide appropriate compliance assurances where reasonably required.

5. INTERNATIONAL DATA TRANSFERS

Where a Subprocessor Processes Customer Data outside the European Economic Area, the United Kingdom or any jurisdiction recognized as providing an adequate level of protection, the Company shall ensure that an appropriate transfer mechanism is implemented in accordance with Applicable Data Protection Laws.

Such mechanisms may include:

  • an adequacy decision adopted by the European Commission;
  • the Standard Contractual Clauses adopted by the European Commission;
  • the UK International Data Transfer Addendum or International Data Transfer Agreement;
  • any other transfer mechanism recognized under Applicable Law.

Where appropriate, supplementary technical and organizational safeguards may also be implemented.

6. CUSTOMER NOTIFICATION

The Company may update the Approved Subprocessor Register from time to time where reasonably necessary to support the provision, maintenance, security or improvement of the Services.

Where required under the Data Processing Agreement, the Company shall provide Customers with prior notice of any intended appointment of a new Subprocessor that will materially affect the Processing of Customer Data.

Notification may be provided by:

  • electronic mail;
  • publication within the customer portal;
  • publication on the Company's website;
  • any other commercially reasonable notification mechanism.

7. CUSTOMER OBJECTION RIGHTS

Where the Customer reasonably believes that the appointment of a proposed Subprocessor would create a material risk to the protection of Customer Data, the Customer may submit a written objection within the period specified in the Data Processing Agreement.

Any objection shall:

  • identify the proposed Subprocessor;
  • specify the legal or technical basis for the objection;
  • describe the material data protection concern.

The Parties shall cooperate in good faith to determine whether a commercially reasonable solution may be implemented.

Where no such solution can reasonably be achieved, the Customer may exercise the termination rights expressly provided in the Agreement.

8. ONGOING SUBPROCESSOR OVERSIGHT

8.1 Third-Party Platforms and Dependencies

The Services may integrate, interoperate or otherwise depend upon Supported Platforms and other Third-Party Dependencies operated, maintained or controlled by independent third parties.

ONLYAI does not own or control such Third-Party Dependencies and cannot guarantee their continued availability, performance, compatibility, security, response times or uninterrupted operation.

Customer acknowledges and agrees that:

(a) third-party terms, technical specifications, APIs, authentication methods, access requirements and usage limitations may change from time to time;

(b) APIs may be modified, restricted, suspended, rate-limited, deprecated or discontinued;

(c) third-party infrastructure, cloud services, hosting environments, database services, content delivery networks, domain name system services, telecommunications networks and other external systems may experience outages, latency, degradation or interruption;

(d) Supported Platforms may restrict, suspend or terminate access to their systems or functionality;

(e) third-party artificial intelligence models or other external technology providers may modify, suspend, restrict or discontinue relevant services; and

(f) such events may temporarily or permanently affect the availability, performance or functionality of the Services.

ONLYAI shall not be deemed in breach of this Agreement or any applicable Service Level Agreement, and shall have no liability for any unavailability, degradation, latency, interruption, failure or loss of functionality to the extent caused by a Third-Party Dependency or any event outside ONLYAI’s reasonable control.

Where reasonably practicable, ONLYAI shall use commercially reasonable efforts to mitigate the impact of a material disruption affecting a Third-Party Dependency and to restore the affected functionality; provided, however, that ONLYAI shall not be required to procure substitute third-party services, incur materially disproportionate costs or redesign the Services solely to remedy a failure attributable to a third party.

8.2 Periodic Review

The Company may periodically evaluate whether each Subprocessor continues to maintain an appropriate level of organizational, technical and contractual safeguards.

Such evaluation may include consideration of:

  • publicly available security certifications;
  • audit reports;
  • regulatory developments;
  • security advisories;
  • vulnerability disclosures;
  • operational incidents;
  • material organizational changes;
  • changes affecting international transfers of Personal Data.

The Company reserves the right to determine the appropriate methodology and frequency of such reviews.

8.3 Security Monitoring

Where commercially reasonable, the Company may monitor significant security developments affecting Subprocessors, including:

  • publicly disclosed cybersecurity incidents;
  • material Personal Data Breaches;
  • changes in regulatory status;
  • suspension or withdrawal of relevant certifications;
  • insolvency proceedings;
  • material degradation of security capabilities.

Where such developments materially affect the Company's ability to comply with the DPA, the Company shall evaluate whether additional safeguards or alternative providers are appropriate.

9. INFORMATION SECURITY REQUIREMENTS

9.1 Minimum Security Standards

The Company seeks to engage only those Subprocessors capable of implementing technical and organizational measures appropriate to the risks associated with the Processing activities entrusted to them.

Without limiting the foregoing, the Company shall seek to ensure that Subprocessors maintain security controls addressing, where appropriate:

  • access governance;
  • authentication;
  • encryption;
  • logging and monitoring;
  • vulnerability management;
  • incident response;
  • personnel confidentiality;
  • business continuity;
  • secure software development;
  • physical security.

9.2 Confidentiality

The Company shall require each Subprocessor to ensure that persons authorized to Process Customer Data are subject to legally enforceable confidentiality obligations or appropriate statutory duties of confidentiality.

9.3 Processing Instructions

Each Subprocessor shall Process Customer Data solely:

  • in accordance with documented instructions received from the Company;
  • for purposes consistent with the services being provided;
  • in compliance with Applicable Data Protection Laws.

Subprocessors shall not determine the purposes or essential means of Processing Customer Data independently.

10. AI SERVICE PROVIDERS

10.1 Artificial Intelligence Providers

Where the Company utilizes third-party providers of Large Language Models ("LLMs"), foundation models or other artificial intelligence services in connection with the provision of the ONLYAI Platform, such providers shall be treated as Subprocessors where they Process Customer Data on behalf of the Company.

10.2 AI Governance

Prior to utilizing an AI service provider for Customer Data Processing, the Company shall, where appropriate, evaluate matters including:

  • contractual privacy commitments;
  • security architecture;
  • data retention practices;
  • model training policies;
  • Zero Data Retention capabilities;
  • geographic location of Processing;
  • applicable certifications;
  • compliance with Applicable Laws.

10.3 Training of Foundation Models

Unless expressly authorized by the Customer in writing or otherwise permitted under the Agreement, the Company shall not knowingly engage an AI service provider that uses Customer Data to train publicly available foundation models.

Where an AI provider offers configurable data retention or model training settings, the Company shall seek to configure such services in a manner consistent with its contractual obligations to Customers.

10.4 AI Routing and Downstream Model Providers

Where the Company utilizes an AI routing, orchestration or gateway provider to facilitate access to one or more underlying artificial intelligence models, the routing provider shall be identified in the Approved Subprocessor Register where it Processes Customer Data on behalf of the Company.

The Company acknowledges that, depending upon the architecture of the relevant AI service, Customer Data may also be transmitted to an underlying model provider selected through such routing infrastructure.

The Company shall seek to ensure that any such Processing is conducted in accordance with the Company’s contractual obligations under the DPA and Applicable Data Protection Laws, including applicable requirements relating to Subprocessors and international transfers.

Where the identity of an underlying model provider is dynamically determined by routing configuration, model selection or service availability, the Company may identify applicable categories of downstream AI providers or maintain relevant information through its Subprocessor governance procedures, to the extent permitted by Applicable Data Protection Laws.

11. CHANGE MANAGEMENT

11.1 Addition of Subprocessors

The Company may appoint additional Subprocessors where reasonably necessary to:

  • provide the Services;
  • improve operational resilience;
  • enhance security;
  • replace existing providers;
  • introduce new functionality;
  • comply with legal or regulatory requirements.

The appointment of a new Subprocessor shall be subject to the governance requirements described in this Schedule.

11.2 Replacement of Subprocessors

Where operationally appropriate, the Company may replace an existing Subprocessor with another provider offering equivalent or enhanced services.

Such replacement shall not constitute a breach of the Agreement provided that:

  • the replacement complies with the DPA;
  • the replacement provides an appropriate level of protection for Customer Data;
  • applicable notification obligations are satisfied.

11.3 Emergency Replacement

Nothing contained in this Schedule shall prevent the Company from replacing a Subprocessor without prior notice where such replacement is reasonably necessary to:

  • address an imminent cybersecurity threat;
  • respond to regulatory action;
  • maintain continuity of the Services;
  • mitigate material operational risks;
  • replace a provider experiencing service disruption.

Where practicable, Customers shall be informed of such replacement as soon as reasonably possible.

12. AUDIT AND COMPLIANCE ASSURANCES

12.1 Compliance Information

Upon reasonable request and subject to appropriate confidentiality obligations, the Company may make available information reasonably necessary to demonstrate that its Subprocessor governance programme complies with the Company's obligations under the Data Processing Agreement.

Such information may include:

  • descriptions of governance procedures;
  • summaries of security measures;
  • audit reports;
  • certifications;
  • compliance attestations;
  • independent assurance reports.

12.2 Protection of Confidential Information

Nothing contained in this Schedule shall require the Company to disclose:

  • confidential commercial information;
  • trade secrets;
  • proprietary security methodologies;
  • internal risk assessments;
  • source code;
  • information that could reasonably compromise the security of the Services or any third party.

12.3 Reliance on Independent Assurance

Where a Subprocessor maintains recognized independent security certifications or audit reports, the Company may rely upon such certifications or reports as part of its ongoing oversight activities.

13. TERMINATION OF SUBPROCESSOR ENGAGEMENT

Upon termination of a Subprocessor's engagement, the Company shall seek to ensure that Customer Data remaining in the possession or control of the Subprocessor is:

  • returned to the Company;
  • securely deleted; or
  • otherwise handled in accordance with Applicable Law and the relevant contractual arrangements,

unless continued retention is required by Applicable Law.

The Company shall maintain appropriate transition arrangements where reasonably necessary to ensure continuity of the Services.

14. APPROVED SUBPROCESSOR REGISTER

The following table identifies the categories of Subprocessors approved as of the Effective Date.

SubprocessorCategory of ServicesPurpose of ProcessingPrimary Processing LocationTransfer Safeguard (where applicable)
Azure OpenAI Service (if utilized)Artificial Intelligence ServicesAI inference and language model processingConfigured deployment regionSCCs or other lawful transfer mechanism, where applicable
OpenAI, LLC (if utilized)Artificial Intelligence ServicesLarge Language Model processingUnited StatesEU Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework, if applicable
Anthropic PBC (if utilized)Artificial Intelligence ServicesLarge Language Model processingUnited StatesEU Standard Contractual Clauses
Supabase Inc. (if utilized)Managed Database ServicesDatabase hosting and storageConfigured deployment regionSCCs, where applicable
Sentry, Inc. (if utilized)Application MonitoringError reporting and diagnosticsUnited StatesSCCs
PostHog, Inc. (if utilized)Product AnalyticsProduct usage analyticsEU / US deploymentSCCs, where applicable
Resend, Inc. (if utilized)Transactional CommunicationsDelivery of transactional emailsUnited StatesSCCs
OnlyFansAPI service provider (onlyfansapi.com)Supported Platform Integration and API ConnectivityFacilitation of authorized connectivity with Customer-controlled Supported Platform accounts, including retrieval, synchronization, transmission and processing of account data, creator and fan communications, messages, media, subscription information, transaction references and related platform dataTo be confirmed with providerAdequacy Decision, SCCs and/or other lawful transfer mechanism, as applicable
OpenRouter service providerArtificial Intelligence Routing and Inference InfrastructureRouting and processing of AI inference requests, including prompts, conversation content, contextual data and AI-generated outputs, and facilitation of access to underlying third-party AI modelsUnited States and/or other locations applicable to selected underlying model providersSCCs, EU-U.S. Data Privacy Framework where applicable, and/or other lawful transfer mechanism
SubprocessorCategory of ServicesPurpose of ProcessingPrimary Processing LocationTransfer Safeguard (where applicable)
Upstash service providerManaged Redis, Queueing and Asynchronous Task InfrastructureCaching, temporary data processing, queue management, asynchronous task execution, event delivery and related operational processingConfigured deployment region and/or provider infrastructure locationSCCs and/or other lawful transfer mechanism, where applicable
Cloudflare, Inc.Object Storage, Content Delivery and Network Security InfrastructureStorage and delivery of Customer media and other files through Cloudflare R2, together with content delivery, network security, DDoS mitigation and related infrastructure servicesConfigured and/or applicable Cloudflare processing locationsSCCs, EU-U.S. Data Privacy Framework where applicable, and/or other lawful transfer mechanism
Neon, Inc.Managed PostgreSQL Database InfrastructurePrimary production database hosting, storage, retrieval and processing of Customer Data and related application dataConfigured deployment regionSCCs and/or other lawful transfer mechanism, where applicable

For the avoidance of doubt, a provider identified as “if utilized” is approved for potential use but may not be actively engaged in the Processing of Customer Data at all times. The inclusion of such provider in this Register shall not constitute a representation that Customer Data is currently transmitted to or Processed by that provider.

15. INTERPRETATION

The Parties acknowledge that:

(a) the Company's technology ecosystem may evolve over time;

(b) operational resilience may require the replacement or addition of infrastructure providers, cloud services or AI providers;

(c) this Schedule establishes governance principles rather than an exhaustive description of every operational relationship maintained by the Company;

(d) the Company retains discretion to determine the specific providers used in connection with the Services, provided that such providers are appointed and managed in accordance with the Data Processing Agreement and Applicable Data Protection Laws.

16. ORDER OF PRECEDENCE

In the event of any inconsistency between this Schedule and the Data Processing Agreement, the provisions of the Data Processing Agreement shall prevail.

This Schedule shall be interpreted in a manner that gives full effect to Article 28 GDPR and the Parties' shared objective of ensuring an appropriate level of protection for Customer Data throughout the processing chain.