Parties

This Services Agreement (the “Agreement”) is made on the Effective Date between:

(1) RISK LAB INNOVATION PTY LTD (ABN 52 695 286 287) trading as Detekta (“Detekta”, “Provider”, “we”, “us”); and

(2) [CUSTOMER LEGAL NAME] (ABN __________________) (the “Customer”, “you”).

(each a “Party” and together the “Parties”).

Background

(A) Detekta provides (i) AML/CTF compliance services and (ii) a Software-as-a-Service compliance platform delivering KYB, KYC, ultimate beneficial owner verification, document and biometric verification, transaction monitoring, and sanctions, PEP and adverse-media screening (the Platform).

(B) The Customer is a reporting entity (or is preparing to operate as a reporting entity) under the AML/CTF Laws and requires the Services to establish and operate its AML/CTF compliance obligations.

(C) The Services comprise two distinct modules — Compliance Services (Schedule A) and Platform Services (Schedule B) — provided on the commercial terms set out in Schedule C.

(D) The Parties agree to enter into this Agreement on the terms set out below.

1. Definitions and Interpretation

Term

Meaning

Affiliate

an entity that Controls, is Controlled by, or is under common Control with, a Party.

AML/CTF Laws

the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the AML/CTF Rules, and any related or successor legislation and regulator instruments.

Applicable Laws

all laws, regulations, rules, regulator policy and orders in force in the Territory that apply to a Party in performing this Agreement, including the AML/CTF Laws and Privacy Laws.

Authorised Users

employees and contractors of the Customer or its Affiliates whom the Customer nominates and grants access to the Platform in accordance with this Agreement.

Business Day

a day other than a Saturday, Sunday or public holiday in Sydney, New South Wales.

Case

a single KYB, KYC, UBO, identity, document or screening verification event initiated through the Platform that consumes one (1) unit of an Included Allowance. Ongoing monitoring and automated periodic re-screening of an already-verified party do not consume a Case.

Compliance Services

the AML/CTF compliance services described in Schedule A.

Confidential Information

information of a confidential nature disclosed by one Party to the other, in any form, including the terms of this Agreement, Customer Data, the Platform, pricing and business information.

Control

the power to direct the management or policies of an entity, whether through ownership of more than 50% of its voting securities, by contract or otherwise.

Customer Data

all data, content and records (including Personal Data) that the Customer, its Authorised Users, its clients or its Affiliates submit to, generate within, or store on the Platform.

Effective Date

the date set out on the cover page of this Agreement, or if none is stated, the date of last signature.

Fees

the fees payable by the Customer as set out in Schedule C.

GST

goods and services tax under the A New Tax System (Goods and Services Tax) Act 1999 (Cth).

Included Allowance

the volume of Cases (stated separately for KYB and KYC) included in the Fees for the relevant period, as set out in Schedule C.

Order Form

Schedule C to this Agreement, and any further order form the Parties agree in writing.

Program Documents

the AML/CTF program, policies, procedures and customer risk-rating methodology in the final form delivered to the Customer under Schedule A.

Initial Term

thirty-six (36) months from the Effective Date.

MLRO

the Customer’s appointed AML/CTF Compliance Officer / Money Laundering Reporting Officer.

Personal Data

has the meaning given to “personal information” in the Privacy Act 1988 (Cth).

Platform Services

the Platform and related services described in Schedule B.

Privacy Laws

the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and any other applicable data-protection law in the Territory.

Services

together, the Compliance Services and the Platform Services.

SMR

a suspicious matter report under the AML/CTF Laws.

Territory

Australia.

Third Party Data Providers

third-party data sources, registries and identity providers used by Detekta to deliver the Platform Services, as listed in Schedule D.

2. Structure of the Services

3. Customer Responsibilities and Regulatory Ownership

4. Term and Renewal

5. Fees and Payment

6. Service Levels and Support

7. Data Protection and Privacy

8. Confidentiality

9. Intellectual Property

10. Third Party Data Providers

11. Warranties

12. Liability and Indemnity

13. Suspension, Termination and Effect

14. Regulatory Compliance, Records and Audit

15. Force Majeure

16. Dispute Resolution

17. General

Execution

Executed as an agreement. Each company may sign in accordance with section 127 of the Corporations Act 2001 (Cth) — by two directors, a director and a company secretary, or (for a sole-director company) the sole director.

Signed for RISK LAB INNOVATION PTY LTD t/a DETEKTA (ABN 52 695 286 287):

Signature of director: ______________________

Signature of director/secretary: ________________

Name: __________________________

Name: __________________________

Office held: ____________________

Office held: ____________________

Date: __________________________

Date: __________________________

Signed for [CUSTOMER LEGAL NAME] (ABN __________):

Signature of director: ______________________

Signature of director/secretary: ________________

Name: __________________________

Name: __________________________

Office held: ____________________

Office held: ____________________

Date: __________________________

Date: __________________________

(If a Party is a sole-director company, only the sole director need sign; strike through the second signature block.)

Schedule A — Compliance Services

This Schedule describes the professional AML/CTF compliance module. It is subject to the warranty standard in clause 11.2 and the liability treatment in clause 12.4. Detekta prepares and supports; the Customer, as reporting entity, decides and files.

A1. AML/CTF Program & Policies

A2. Back-book Remediation & Ongoing CDD

A3. Case Review & Outsourced Compliance Operations

A4. MLRO Support (division of responsibility)

The Customer appoints and maintains its own MLRO. Detekta supports the role but does not perform it. Specifically:

Activity

Responsibility

Investigate alerts; gather evidence; draft SMRs and reports

Detekta (prepares)

Review and approve reports and SMRs; decide whether to report

Customer’s MLRO (decides)

Lodge SMRs and reports with AUSTRAC

Detekta, only on the MLRO’s express written approval and instruction

Quarterly MLRO meeting (cases, filings, program health)

Detekta facilitates; Customer’s MLRO chairs

A5. Learning & Development

A6. External Audit Readiness

A7. Customer dependencies

Detekta’s delivery of the Compliance Services depends on the Customer providing complete and accurate information, file extracts, validations and access, and reasonable personnel availability, as further described in Schedule C. Timeframes run from the Customer meeting these dependencies.

Schedule B — Platform Services

This Schedule describes the Platform (SaaS) module. It is subject to the warranty standard in clause 11.3.

B1. Platform capabilities

B2. Case definition and allowances

A Case is a single initiated KYB, KYC, UBO, identity, document or screening verification event. Ongoing monitoring and automated periodic re-screening of an already-verified party do NOT consume a Case. The fixed Fee covers the estimated KYB and KYC volumes set out in Schedule C; Cases above those volumes are billed monthly in arrears at the overage rates in Schedule C, stated separately for KYB and KYC as the rates differ.

B3. Service Levels

Element

Target

Platform availability

99.95% per calendar month (excl. scheduled maintenance, Force Majeure, Customer-side outages, and Third Party Data Provider unavailability outside Detekta’s control)

Support hours

Business Hours (9:00am–6:00pm Sydney, Mon–Fri excl. public holidays); critical incidents 24/7

P1 (critical) — response / resolution

30 minutes / 4 hours

P2 (high) — response / resolution

2 Business Hours / 1 Business Day

Service credits

As set out below (Customer’s sole and exclusive remedy for failure to meet availability)

Monthly availability

Service credit (% of monthly Platform Fee)

< 99.95% and ≥ 99.0%

5%

< 99.0%

10%

Availability is measured on the Platform and excludes unavailability of Third Party Data Providers. This 99.95% commitment mirrors the service level Detekta receives from its primary orchestration provider.

B4. Hosting and security

Customer Data is hosted in Australia. Detekta maintains encryption in transit and at rest, role-based access control, multi-factor administrative authentication, logging and monitoring, vulnerability management, and documented business continuity and disaster recovery, as further described in Schedule D.

Schedule C — Commercial Terms (Order Form)

Complete the fields below per engagement. All amounts are in AUD and exclusive of GST unless stated otherwise.

C1. Parties and contacts

Customer legal name / ABN

______________________________________________

Detekta contact

Ricardo Maifrino — ricardo@detekta.ai

Customer primary contact

______________________________________________

Customer billing contact

______________________________________________

Customer MLRO

______________________________________________

C2. Term and modules

Initial Term

Thirty-six (36) months from the Effective Date

Modules included

☐ Compliance Services (Schedule A) ☐ Platform Services (Schedule B)

Territory

Australia

C3. Fees

Fixed monthly Fee (covers all included modules and allowances):

Fee component

Basis

Amount (ex GST)

Fixed monthly Fee

per month, in advance

____________

— covering: program, remediation, case review, MLRO support, monitoring, training, integrations, and checks up to the estimated volumes in C4

included

One-off and variable components (complete as applicable):

Category

Basis

Amount (ex GST)

Implementation / setup

one-off

____________

System integration — per system (e.g. Ignition, Xero)

one-off per system

____________

KYB verification — overage

per Case

____________

KYC verification — overage

per Case

____________

Transaction monitoring (if priced separately)

per month

____________

MLRO support (if priced separately)

per month

____________

Additional / bespoke services

as quoted

____________

C4. Included volumes and overage

The fixed monthly Fee covers the estimated check volumes below over the Initial Term. Cases above these volumes are billed monthly in arrears at the KYB and KYC overage rates in C3 — stated separately by check type, as the rates differ.

Check type

Estimated volume included (over the 36-month term)

Overage rate (ex GST)

KYB Cases

____________

__________

KYC Cases

____________

__________

C5. Payment

Billing cycle

Monthly in advance

Payment terms

Due within ten (10) days of invoice date, or by automatic card debit on/after the first of the month

Payment method

☐ EFT / bank transfer ☐ Automatic card debit (Stripe / Pin Payments / equivalent)

Overage billing

In arrears, added to the following month’s invoice or debit

C6. Third-party cost pass-through

Where a Third Party Data Provider increases the charges it imposes on Detekta, Detekta may pass through the increase (by no more than the same percentage) on thirty (30) days’ written notice. Otherwise Fees are fixed for the Initial Term save for the renewal adjustment in clause 4.4.

C7. Group and referral incentives (optional)

Group discount

____% off each additional Customer-group entity onboarded

Referral credit

____% of each referred customer’s monthly fee, credited to the Customer for ____ months per successful referral (stacking)

Schedule D — Data Processing Addendum (Australia)

This Addendum applies to Personal Data processed by Detekta on behalf of the Customer under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It forms part of the Agreement.

D1. Roles and processing

The Customer determines the purposes and means of processing Customer Data; Detekta processes it on the Customer’s behalf and on its documented instructions, except where required by Applicable Laws. Where the Customer processes data for its own clients who are the controllers, Detekta acts as a downstream processor.

Subject matter and purpose: KYB/KYC verification, sanctions/PEP/adverse-media screening, transaction monitoring, compliance reporting and related processing to support the Customer’s AML/CTF obligations. Duration: the term of the Agreement plus the 7-year AML/CTF retention period.

D2. Categories of data

Data subjects: the Customer’s clients (individuals and representatives of entities), Authorised Users, and other persons whose data is submitted. Categories: identification and contact data, identity-document details, biometric data (where used for liveness), financial and transactional data, KYB/KYC outcomes, screening results, and audit and access logs.

D3. Detekta obligations

D4. Third Party Data Providers / sub-processors

Detekta uses the following Third Party Data Providers / sub-processors (complete per engagement; Australian domestic engagement shown as default). Detekta will notify the Customer of any addition or replacement on at least thirty (30) days’ notice; if the Customer reasonably objects on data-protection grounds, the Parties will work in good faith on an alternative.

Provider

Purpose

Location

FrankieOne (Frankie Financial Pty Ltd)

KYB/KYC orchestration

Australia

Australian registries / credit bureaus (as applicable)

Company, identity and credit data

Australia

Amazon Web Services (Sydney)

Infrastructure hosting

Australia

Supabase (AU region)

Application database, auth, functions

Australia

__________________

________________

__________

D5. Technical and organisational measures

D6. Breach notification

Detekta will notify the Customer without undue delay after becoming aware of an eligible data breach affecting Customer Data, providing the nature of the breach, the categories and approximate numbers of records affected, likely consequences, and measures taken or proposed — to enable the Customer to meet its Notifiable Data Breaches obligations.

— End of template —

Detekta — Detect. Decide. Defend. · Commercial in confidence · This is a working template; commercial terms in Schedule C are completed per engagement.