# RBEK SDK — Enterprise Ultra Premium License Agreement (EUPLA)

**Version 1.3 — Final**  
**Proprietary, Restricted, Regulated and High-Risk Use**

Copyright © 2026 RBEK Runtime Technologies. All rights reserved.

## 1. Parties

This License Agreement (“Agreement”) is entered into between:

**RBEK Runtime Technologies** (“Licensor”),

and

the acquiring entity (“Licensee”), including, only where expressly authorized under this Agreement or an applicable Order Form, its subsidiaries, authorized internal teams, regulated units, and controlled entities.

## 2. Grant of License

Subject to the Licensee's compliance with this Agreement, the Licensor grants the Licensee a limited, non-exclusive, non-transferable and non-sublicensable license to install and use the RBEK SDK solely for authorized business purposes, including:

- internal development;
- integration with corporate systems;
- execution of critical workloads;
- regulated CI/CD pipelines;
- high-risk enterprise operations;
- regulated environments, including finance, healthcare, energy and government;
- compatibility and interoperability testing with the RBEK runtime;
- security, compliance and resilience testing;
- operations subject to internal or external audit.

No public redistribution rights are granted.

Except where expressly permitted by this Agreement, an applicable Order Form, or mandatory applicable law, the Licensee may not make the SDK available outside its authorized organizational environment.

## 3. Authorized Users and Scope of Use

The Licensee may permit access to and use of the SDK by:

- employees;
- authorized technical teams;
- security and compliance teams;
- DevSecOps teams;
- incident response teams;
- internal audit teams;
- external auditors acting under appropriate confidentiality obligations;
- controlled subsidiaries expressly covered by the applicable license or Order Form;
- regulated entities under the Licensee's direct control where expressly authorized.

External consultants may access the SDK only where:

1. their access is reasonably necessary for services performed for the Licensee;
2. they are bound by written confidentiality and security obligations no less protective than those applicable to the Licensee;
3. they use the SDK solely for the benefit of the Licensee; and
4. the Licensee remains responsible for their compliance.

Competitors of the Licensor may not access the SDK without the Licensor's prior written authorization, except to the extent that a contrary right arises under mandatory applicable law.

## 4. Restrictions

**Except to the extent expressly permitted by mandatory applicable law, including applicable rights under Directive 2009/24/EC, the Licensee shall not:**

- modify, adapt, translate, decompile, disassemble or reverse engineer the SDK;
- redistribute, publish, sell, rent, lease or sublicense the SDK;
- make the SDK available outside the Licensee's authorized organizational environment;
- use the SDK or confidential technical information to create an unauthorized substantially similar implementation of protected RBEK software;
- remove or alter copyright notices, proprietary notices or integrity metadata;
- bypass or materially interfere with security, integrity or verification mechanisms;
- use the SDK in weapons systems, cyber-weapons, unlawful offensive surveillance or prohibited military applications;
- use non-public SDK source code, confidential technical information or protected implementation details to train an AI model whose primary purpose is to reproduce protected RBEK software functionality or expression;
- knowingly provide access to persons or entities where such access would violate applicable sanctions or export-control laws.

Nothing in this Clause prohibits activity that cannot lawfully be restricted by contract.

### 4.1 Mandatory Software Rights and EU Interoperability Safeguard

Nothing in this Agreement is intended to exclude or restrict rights that cannot lawfully be excluded under applicable software law.

In particular, where Directive 2009/24/EC or corresponding national legislation applies, a lawful user may exercise applicable mandatory rights relating to:

- the making of a necessary backup copy;
- observation, study or testing of the functioning of the program while performing acts the user is entitled to perform; and
- decompilation or translation of code where, and only to the extent, the statutory requirements for interoperability with independently created software are satisfied.

Where decompilation is permitted for interoperability, the information obtained may only be used within the limits permitted by applicable law, including restrictions on unrelated use, unnecessary disclosure and development of software that unlawfully infringes protected expression.

Where reasonably practicable, the Licensee is encouraged to request available interoperability information from the Licensor before undertaking decompilation.

Such a request is not intended to operate as a contractual waiver or restriction of any mandatory statutory right.

## 5. Intellectual Property

The SDK and all associated proprietary software, source code, object code, documentation, protected architecture, trademarks and other intellectual property supplied by the Licensor remain the property of the Licensor or its licensors.

No ownership rights are transferred to the Licensee.

The Licensee receives only the limited rights expressly granted under this Agreement.

Nothing in this Agreement grants ownership over independently created software developed by the Licensee.

## 6. Confidentiality

Subject to the exclusions below, non-public information disclosed by the Licensor in connection with the SDK shall be treated as Confidential Information where its nature or circumstances of disclosure would reasonably indicate confidentiality.

Confidential Information may include:

- non-public SDK source code;
- non-public technical documentation;
- proprietary protocols;
- non-public architecture;
- internal security mechanisms;
- anti-tampering mechanisms;
- cryptographic verification processes;
- non-public technical metrics;
- proprietary implementation information;
- non-public vulnerability information.

Confidential Information does **not** include information that the Licensee can demonstrate:

1. was lawfully known to it without confidentiality obligation before disclosure;
2. becomes publicly available without breach of this Agreement;
3. is received lawfully from a third party without confidentiality restriction;
4. is independently developed without use of the Licensor's Confidential Information; or
5. must be disclosed pursuant to applicable law, regulation, court order or binding regulatory requirement.

Where legally permitted, the Licensee shall provide reasonable notice before compelled disclosure and shall disclose only the information legally required.

Confidentiality obligations survive termination for ten (10) years, except that qualifying trade secrets shall remain protected for so long as they retain trade-secret status under applicable law.

## 7. Security, Integrity, Logging and Telemetry

The SDK and/or separately licensed RBEK runtime components **may**, depending on the applicable deployment and configuration, support:

- integrity verification;
- technical event logging;
- unauthorized execution protection;
- anti-tampering controls;
- cryptographic verification;
- security monitoring;
- misuse detection;
- operational telemetry.

No remote telemetry, monitoring or transfer of operational information to the Licensor shall be deemed enabled merely by this Agreement.

Where remote telemetry or monitoring is used, its existence, purpose and applicable configuration shall be documented for the relevant deployment or agreed in the applicable Order Form, service documentation or other written agreement.

The Licensee shall not unlawfully bypass, disable or interfere with security or integrity mechanisms that are required for the licensed deployment.

### 7.1 Data Protection and GDPR

The SDK and associated RBEK components shall be designed and configured, where applicable, with the objective of minimizing unnecessary processing of personal data.

Technical telemetry is intended primarily for operational, security, integrity, licensing or diagnostic purposes.

However, technical information may constitute personal data under applicable law depending on its content and context.

Where personal data is processed, the relevant parties shall comply with applicable data-protection legislation, including the General Data Protection Regulation where applicable.

This may require, as appropriate:

- an applicable lawful basis for processing;
- purpose limitation;
- data minimization;
- transparency;
- appropriate retention periods;
- appropriate technical and organizational security measures;
- mechanisms supporting applicable data-subject rights;
- appropriate processor/controller contractual terms where required.

The roles of Licensor and Licensee as controller, processor, independent controllers or otherwise shall be determined by the actual processing activities and applicable contractual arrangements, rather than by this Agreement alone.

Where required, the parties may enter into a separate Data Processing Agreement.

## 8. Audit and Compliance Verification

The Licensor may request reasonable information necessary to verify material compliance with this Agreement.

Except where reasonably required following a security incident, suspected material breach, regulatory requirement or credible evidence of misuse:

- ordinary compliance audits shall not occur more than once in any twelve-month period;
- the Licensor shall provide reasonable prior written notice;
- the scope shall be limited to information reasonably necessary to verify compliance;
- audits shall be conducted so as to minimize disruption to critical operations;
- the Licensor shall not require access to unrelated personal data, customer data, trade secrets or security-sensitive systems where equivalent evidence can reasonably establish compliance.

Compliance evidence may include, where relevant:

- installation inventory;
- authorized-user records;
- license usage records;
- access-control evidence;
- relevant execution records;
- security-control evidence;
- incident records relating to the SDK;
- relevant segregation-of-duties evidence.

Where appropriate, compliance may be verified by an independent qualified auditor bound by confidentiality obligations.

Existing ISO 27001, SOC 2, NIS2-related or comparable evidence may be used where reasonably sufficient.

Nothing in this Clause requires a party to violate applicable law, professional secrecy, regulatory restrictions or third-party confidentiality obligations.

## 9. Protection Against Competitive Misuse

The Licensee shall not use non-public SDK source code, Confidential Information or proprietary implementation details supplied by the Licensor primarily for the purpose of:

- creating an unauthorized copy of protected RBEK software;
- reproducing protected implementation expression;
- circumventing licensed technical controls;
- enabling unauthorized redistribution;
- misappropriating the Licensor's trade secrets.

Nothing in this Clause prohibits:

- independent development;
- lawful interoperability;
- legitimate security research authorized by the Licensor;
- activity permitted under mandatory applicable law;
- development based solely on publicly available information, general knowledge, skills or experience.

No independent post-termination non-competition obligation is created by this Clause.

Obligations concerning intellectual property, confidentiality and trade secrets survive as provided elsewhere in this Agreement and applicable law.

## 10. Export Control and Sanctions

The Licensee shall comply with export-control, sanctions and technology-transfer laws applicable to its use of the SDK.

The Licensee shall not knowingly:

- export or transfer the SDK in violation of applicable export restrictions;
- provide access to sanctioned or prohibited persons or entities where prohibited by law;
- use the SDK in a manner prohibited by applicable military or dual-use restrictions;
- circumvent legally applicable technology-transfer controls.

The Licensee shall not be required to comply with a contractual restriction to the extent that doing so would itself violate applicable mandatory law.

## 11. Ultra Premium Support and SLA

Support services, service levels, response times, maintenance obligations, availability commitments and operational guarantees are governed exclusively by an applicable Order Form, Service Level Agreement or other written agreement executed between the parties.

Such documents may specify:

- support tiers;
- response windows;
- incident severity classifications;
- escalation procedures;
- maintenance schedules;
- availability commitments;
- service credits;
- commercial terms.

Custom development, professional services and implementation services are not included unless expressly agreed in writing.

## 12. Indemnification

Subject to applicable law, the Licensee shall indemnify and defend the Licensor against third-party claims arising directly from the Licensee's:

- unauthorized redistribution of the SDK;
- material breach of confidentiality obligations;
- knowing infringement arising from prohibited modification or redistribution;
- violation of applicable export-control or sanctions laws;
- prohibited use expressly identified in this Agreement;
- unlawful use of the SDK caused by the Licensee's material breach.

Indemnification is subject to the following procedure:

1. the Licensor shall provide reasonably prompt notice of the relevant claim;
2. the Licensee shall be permitted to control the defense and settlement, subject to reasonable cooperation by the Licensor;
3. the Licensor may participate through counsel at its own expense; and
4. the Licensee shall not enter into a settlement that admits wrongdoing by, imposes non-monetary obligations on, or materially prejudices the Licensor without prior written consent, not to be unreasonably withheld.

Failure to provide immediate notice does not eliminate indemnification except to the extent the delay materially prejudices the defense.

## 13. Limitation of Liability

To the maximum extent permitted by applicable law, the Licensor's aggregate liability arising out of or relating to this Agreement shall not exceed the fees paid or payable by the Licensee for the affected SDK license or applicable Order Form during the twelve (12) months preceding the event giving rise to liability.

### 13.1 Pre-Release Versions

For Alpha, Beta, Release Candidate or other expressly identified pre-release versions, where application of the preceding limitation would result in a liability cap below EUR 1,000, the aggregate contractual cap shall instead be EUR 1,000.

**This EUR 1,000 floor is an intentional allocation of risk.**

Pre-release software may contain defects, incomplete functionality or material changes and shall not be treated as production-certified unless expressly stated otherwise in writing.

### 13.2 Exceptions

No limitation or exclusion in this Agreement shall apply to the extent that liability cannot lawfully be limited or excluded.

Subject to mandatory applicable law, the contractual limitation shall not apply to liability arising from:

- willful misconduct (*dolo*);
- gross negligence (*culpa grave*), where exclusion is not permitted;
- infringement or misappropriation of the other party's intellectual property rights;
- material breach of confidentiality obligations.

To the maximum extent permitted by applicable law, neither party shall be liable for indirect, incidental, special or consequential damages, except where such exclusion is prohibited by law.

## 14. Term and Termination

This Agreement remains effective for the applicable license term unless terminated earlier in accordance with its terms.

The Licensor may terminate the Agreement for material breach where:

1. the breach is incapable of remedy; or
2. where capable of remedy, the Licensee fails to cure the breach within thirty (30) days after written notice.

The Licensor may suspend or terminate more rapidly where reasonably necessary due to:

- unlawful use;
- material security compromise;
- intentional unauthorized redistribution;
- sanctions or export-control violation;
- deliberate misuse creating substantial risk to the Licensor or third parties.

Upon termination, the Licensee shall cease unauthorized use and delete or return copies of the SDK as required, except for copies that must be retained by law, regulatory obligation or immutable backup policy.

Any retained copy remains subject to confidentiality and use restrictions and may not be used operationally unless legally required.

## 15. Governing Law and Jurisdiction

This Agreement is governed by the laws of Portugal, without prejudice to mandatory provisions of applicable European Union law.

Subject to mandatory jurisdictional rules, the courts of the Autonomous Region of Madeira, Portugal shall have exclusive jurisdiction over disputes arising out of or relating to this Agreement.

## 16. Reservation of Rights

All rights not expressly granted under this Agreement are reserved by the Licensor.

No implied license is granted by estoppel, exhaustion or otherwise, except where such rights arise under mandatory applicable law.

## 17. Open Source and Third-Party Components

The SDK may include, depend upon, or interoperate with third-party software and open-source components.

Where required, applicable third-party notices and licenses shall be provided in a NOTICE file, dependency manifest, accompanying documentation or other appropriate distribution material.

Third-party components remain governed by their respective licenses.

Nothing in this Agreement is intended to restrict rights granted directly to the Licensee under applicable third-party or open-source licenses.

Where a third-party license grants rights broader than this Agreement with respect to that third-party component, the third-party license governs that component.

## 18. Force Majeure

Neither party shall be liable for delay or failure to perform obligations caused by events beyond its reasonable control, including:

- natural disasters;
- widespread telecommunications or infrastructure failures;
- war or armed conflict;
- terrorism;
- large-scale cyberattacks;
- governmental measures;
- regulatory prohibitions;
- widespread cloud or energy infrastructure failure.

The affected party shall use reasonable efforts to mitigate the effects of the event and resume performance when reasonably practicable.

Payment obligations accrued before the force-majeure event are not automatically extinguished.

## 19. Order of Precedence

Where the Licensee has entered into an Order Form, SLA, Data Processing Agreement or other written agreement with the Licensor, the following order of precedence applies in the event of direct conflict, unless expressly stated otherwise:

1. Data Processing Agreement, solely for data-protection matters;
2. applicable Order Form;
3. applicable SLA, solely for service-level matters;
4. this Agreement;
5. general documentation.

A document modifies this Agreement only to the extent that it expressly identifies the provision being modified or clearly addresses the same subject matter.

## 20. Entire Agreement and Amendments

This Agreement, together with applicable Order Forms and incorporated agreements, constitutes the entire agreement between the parties concerning the licensed SDK and supersedes prior representations concerning that subject matter.

Any amendment must be made in writing by authorized representatives of the parties, except that the Licensor may issue a new license version for future releases.

A new license version shall not retroactively alter rights already granted for a previously acquired version unless the parties expressly agree otherwise.

## 21. Severability

If any provision is held invalid, unlawful or unenforceable, that provision shall be interpreted or limited to the minimum extent necessary to make it enforceable where legally possible.

The remaining provisions shall continue in effect.

## 22. No Waiver

Failure or delay in enforcing a provision does not constitute a waiver of that provision or any other right.

## 23. Assignment

The Licensee may not assign this Agreement without the Licensor's prior written consent, except as expressly permitted in an applicable Order Form or in connection with a corporate reorganization where the successor assumes all applicable obligations and is not a prohibited competitor or sanctioned entity.

The Licensor may assign this Agreement in connection with a merger, corporate restructuring, financing or transfer of substantially all relevant business assets, subject to applicable law.

---

**END OF RBEK SDK ENTERPRISE ULTRA PREMIUM LICENSE AGREEMENT — VERSION 1.3 FINAL**

