Legal / Terms of Service

Master Service and Service Level Agreement

The standard terms, conditions and service levels applicable to every Bridge Network product and service — what Breeze commits to, what the Customer is responsible for, and how the relationship is governed.

Effective 21 August 2026

This Agreement is made between BREEZE FZE, a free zone establishment incorporated and existing under the laws of the Federal Republic of Nigeria with its registered office at Itana FZ, Alaro City, Lekki Free Trade Zone, Lekki, Lagos State, Nigeria, operator of the Bridge Trade Network (“Breeze”, which expression shall where the context admits include its successors in title, permitted assigns and affiliates), and the person identified as the Customer in the Order Form (the “Customer”, which expression shall where the context admits include its successors in title and permitted assigns). Breeze and the Customer are each referred to as a “Party” and together as the “Parties”.

It applies to BridgeOS, Express, Vault (including the Vault NRS E-Invoice Module), Radar, Accelerate, Threshold and Terminal, and to both individual and corporate customers. It is reviewed annually, or on a material change in Applicable Laws.

Background

(A)Breeze operates the Bridge Trade Network, a digital trade infrastructure platform built on BridgeOS, which structures, verifies and executes trade transactions and which digitises trade documents and workflows in line with international legal standards including the UNCITRAL Model Law on Electronic Transferable Records, the eUCP and the eURC.

(B)The Platform is composed of core primitives (Origin, Verify, Folder and Transfer) and an application layer comprising Express, Vault, Radar, Accelerate, Threshold and Terminal, each of which may be subscribed to independently or in combination.

(C)Vault includes the Vault NRS E-Invoice Module, through which a Customer may create, sign, transmit for clearance and archive electronic invoices in the structure prescribed by the Nigeria Revenue Service under the National e-Invoicing and Electronic Fiscal System, also known as the Merchant Buyer Solution.

(D)The Customer wishes to subscribe for and use the Services, and Breeze is willing to provide the Services, on the terms and subject to the conditions of this Agreement.

(E)This Agreement records the terms and conditions between Breeze and the Customer, sets out the service levels which Breeze commits to meet, and establishes the standards of availability, response, resolution of issues and data security applicable to the Services.

01

Definitions and interpretation

1.1In this Agreement, unless the context otherwise requires, the following expressions have the following meanings.

Defined termMeaning
Access Point Provider or APPAn entity accredited to transmit and receive electronic invoices on the Merchant Buyer Solution network on behalf of taxpayers.
AffiliateIn relation to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with that Party.
AgreementThis master service and service level agreement, together with its Schedules, each Order Form and any document expressly incorporated by reference.
Applicable LawAll laws, statutes, regulations, directives, regulatory guidelines, licence conditions and binding codes of practice applicable to a Party or to the performance of this Agreement, in any relevant jurisdiction.
Authorised UserAn employee, officer, agent or contractor of the Customer whom the Customer authorises to access the Platform using credentials issued under this Agreement.
AvailabilityThe percentage of time in a Measurement Period during which a Module is available for use, calculated in accordance with clause 8.3.
Availability TargetThe availability percentage specified for a Module and Service Tier in Schedule 2.
Bridge Network or PlatformThe Bridge Trade Network operated by Breeze, comprising BridgeOS, the Modules, the dashboard, the APIs, the Documentation and all associated infrastructure.
BridgeOSThe underlying trust and execution layer of the Platform, comprising the Origin, Verify, Folder and Transfer primitives.
Business DayA day other than a Saturday, Sunday or public holiday in Nigeria and in the jurisdiction in which the Customer is established.
Business Hours08:00 to 18:00 Gulf Standard Time on a Business Day, or such other hours as are stated for the Customer’s Service Tier in Schedule 3.
Confidential InformationHas the meaning given in clause 17.1.
Customer DataAll data, documents, records, instructions, files and content submitted to, generated within or transmitted through the Platform by or on behalf of the Customer, including Trade Documents and Personal Data.
DocumentationThe user guides, API reference materials, technical specifications and support documentation made available by Breeze in respect of the Services, as updated from time to time.
DowntimeAny period during which a Module is not Available, excluding Excluded Downtime.
Excluded DowntimeThe categories of unavailability listed in clause 8.5, which are disregarded in calculating Availability.
FeesThe charges payable by the Customer for the Services as set out in Schedule 6 and the Order Form.
Force Majeure EventHas the meaning given in clause 27.1.
IncidentAny unplanned interruption to, or reduction in the quality of, a Module or the Services reported by the Customer or detected by Breeze.
Intellectual Property RightsPatents, trade marks, service marks, trade names, domain names, copyright, database rights, design rights, rights in know how and trade secrets, and all other intellectual property rights, whether registered or unregistered.
Invoice Reference Number or IRNThe unique reference number issued by the Nigeria Revenue Service upon clearance of an electronic invoice.
MBS or Merchant Buyer SolutionThe National e-Invoicing and Electronic Fiscal System operated by the Nigeria Revenue Service.
Measurement PeriodEach calendar month during the Term.
MLETRThe UNCITRAL Model Law on Electronic Transferable Records adopted in July 2017, and any enactment of it in a relevant jurisdiction.
ModuleAny of the products or functional components of the Platform described in Schedule 1, whether a BridgeOS primitive or an application layer product.
NDPAThe Nigeria Data Protection Act 2023 and any subsidiary legislation, regulation or guidance issued under it.
NRSThe Nigeria Revenue Service, being the federal revenue authority of the Federal Republic of Nigeria and successor to the Federal Inland Revenue Service.
Order FormThe subscription document executed by the Parties in the form of Schedule 7, specifying the Modules subscribed, the Service Tier, the Fees and the Subscription Term.
PAPSSThe Pan-African Payment and Settlement System.
Personal DataHas the meaning given to it under the NDPA and, where applicable to the Customer, under any other data protection law applicable to the processing.
ResolutionThe restoration of a Module to normal operation, or the delivery of a permanent fix that removes the effect of an Incident.
ResponseThe first substantive acknowledgement by Breeze of a reported Incident, confirming receipt, assigning a Severity Level and identifying the owner of the Incident.
Service CreditThe credit calculated in accordance with Schedule 2 and payable in accordance with clause 13.
Service LevelsThe availability, performance, response and resolution commitments set out in clauses 8 to 12 and Schedules 2 and 3.
Service TierThe Essential, Professional or Enterprise tier selected in the Order Form.
ServicesThe provision of access to and use of the subscribed Modules, together with the support, maintenance and ancillary services provided under this Agreement.
Severity LevelThe classification of an Incident as P1, P2, P3 or P4 in accordance with Schedule 3.
Subscription TermThe initial period stated in the Order Form and each renewal period.
System Integrator or SIAn entity accredited to integrate a taxpayer’s systems with the Merchant Buyer Solution.
Third Party DependencyAny system, network, service or infrastructure not owned or operated by Breeze on which the Services depend, including the MBS, PAPSS, banks and correspondent banks, distributed ledger networks, cloud hosting providers, identity and sanctions data providers, telecommunications networks and the public internet.
Trade DocumentAny document created, stored, verified, signed, transferred or transmitted through the Platform, including invoices, purchase orders, bills of lading, letters of credit, bank guarantees, promissory notes, certificates and packing lists.
WorkaroundA temporary means of avoiding or materially reducing the effect of an Incident pending Resolution.

1.2In this Agreement, unless the context otherwise requires: (a) the singular includes the plural and vice versa; (b) a reference to a clause or Schedule is a reference to a clause of or Schedule to this Agreement; (c) a reference to a statute or statutory provision is a reference to it as amended, extended or re-enacted from time to time; (d) headings are for convenience only and do not affect interpretation; (e) “including”, “in particular” and similar expressions are illustrative and do not limit the words preceding them; (f) “writing” includes email and communications through the Platform, but excludes any other instant messaging medium; and (g) a reference to a person includes a natural person, corporate body, partnership, trust, government authority or unincorporated association.

1.3The Schedules form part of this Agreement and have the same force and effect as if set out in the body of this Agreement.

02

Structure of the agreement and order of precedence

2.1This Agreement is a master agreement. The specific Modules subscribed by the Customer, the applicable Service Tier, the Fees and the Subscription Term are set out in one or more Order Forms. Each executed Order Form incorporates this Agreement and does not constitute a separate contract.

2.2If there is a conflict or inconsistency between the documents forming this Agreement, the following order of precedence applies, with the higher ranked document prevailing to the extent of the inconsistency only:

(a)any provision of Applicable Law which cannot be varied by agreement;

(b)Schedule 5 (Vault NRS E-Invoice Module), in respect of the Vault NRS E-Invoice Module only;

(c)the executed Order Form, but only where it expressly states the clause of this Agreement it is intended to vary;

(d)the body of this Agreement;

(e)Schedules 1 to 4, 6 and 7; and

(f)the Documentation.

2.3Breeze may update this Agreement to reflect changes in Applicable Law, regulatory direction, security requirements or Module functionality. Breeze shall give the Customer not less than thirty (30) days written notice of any update that materially and adversely affects the Customer, save where a shorter period is required by Applicable Law or by a regulator, in which case Breeze shall give as much notice as is reasonably practicable. If the Customer objects to a material adverse update, the Customer may terminate the affected Module on written notice given before the update takes effect, and shall receive a pro rata refund of Fees prepaid in respect of the unexpired period.

2.4No update to this Agreement shall reduce an Availability Target, extend a Response or Resolution target, or dilute a data security commitment, during a Subscription Term already paid for, except with the Customer’s written consent.

03

Commencement, term and renewal

3.1This Agreement commences on the Effective Date and continues until terminated in accordance with clause 29.

3.2Each subscription commences on the date stated in the Order Form and continues for the Subscription Term. Unless a Party gives written notice of non-renewal not less than sixty (60) days before the end of the then current Subscription Term, the subscription renews automatically for successive periods equal in length to the initial Subscription Term.

3.3Where an Order Form is expressed to be for a pilot, proof of concept or evaluation, the subscription expires automatically at the end of the stated period and does not renew. The Parties shall enter into a further agreement only on the successful conclusion of that pilot and mutual acceptance of terms.

04

Grant of access and scope of services

4.1Subject to the Customer’s compliance with this Agreement and payment of the Fees, Breeze grants the Customer a non-exclusive, non-transferable, non-sublicensable right for the Subscription Term to access and use the subscribed Modules, through the dashboard and the APIs, for the Customer’s internal business purposes and for the purposes described in Schedule 1.

4.2Breeze shall provide the Services with reasonable skill and care, in a professional and workmanlike manner, using appropriately qualified personnel, and in accordance with the Service Levels, the Documentation and Applicable Law.

4.3Breeze retains discretion over the technical means of delivering the Services, including hosting locations (subject to clause 15.9), architecture, subcontracting (subject to clause 15.6) and the sequence of releases, provided that no such decision reduces the Service Levels or the security measures in Schedule 4.

4.4Where the Order Form provides for white label or embedded deployment, the Customer may make the subscribed Modules available to its own customers under the Customer’s brand, provided that the Customer: (a) remains fully responsible for the acts and omissions of those end users as if they were its own; (b) imposes on them terms no less protective of Breeze than this Agreement; and (c) does not represent that Breeze owes those end users any direct obligation.

4.5Features designated as beta, pilot, preview or trial are provided on an “as is” basis, are excluded from the Service Levels and Service Credits, and may be modified or withdrawn at any time.

05

Onboarding, verification and account administration

5.1Before activation, the Customer shall complete Breeze’s onboarding process, including customer due diligence, know your customer and know your business verification through Radar, and shall provide all information and documents Breeze reasonably requires to satisfy its regulatory obligations.

5.2Breeze shall complete onboarding verification within five (5) Business Days of receipt of a complete and accurate submission, save where a referral, enhanced due diligence, sanctions match or regulatory hold requires longer, in which case Breeze shall notify the Customer of the delay and, so far as it is lawfully able, of the reason for it.

5.3The Customer shall notify Breeze in writing within ten (10) Business Days of any material change to the information provided under clause 5.1, including a change of control, change of directors or beneficial owners, change of registered office, loss or suspension of any licence, or the commencement of any insolvency process.

5.4The Customer is responsible for the administration of Authorised Users, including issuing, monitoring and revoking access, applying role based permissions, and ensuring that credentials are not shared. The Customer shall notify Breeze immediately on becoming aware of any unauthorised access to or use of the Platform.

5.5Acts and omissions of Authorised Users are deemed to be the acts and omissions of the Customer.

06

Customer obligations and acceptable use

6.1The Customer shall: (a) use the Services only for lawful purposes and in accordance with the Documentation; (b) ensure that all Customer Data submitted is accurate, complete, current and lawfully obtained; (c) obtain and maintain all consents, licences, permits and authorisations required for its underlying trade, tax or financing transactions; (d) maintain the systems, connectivity and browser or client software required to access the Platform; and (e) cooperate reasonably with Breeze in the investigation and resolution of Incidents.

6.2The Customer shall not, and shall procure that Authorised Users do not: (a) submit false, forged, fraudulent or misleading documents or data; (b) use the Services to facilitate money laundering, terrorist financing, sanctions evasion, trade based financial crime, tax evasion or duplicate financing of the same receivable; (c) attempt to gain unauthorised access to the Platform or to any other user’s data; (d) reverse engineer, decompile, scrape or create derivative works from the Platform, except to the extent permitted by Applicable Law which cannot be excluded; (e) resell, sublicense or make the Services available to a third party except as permitted under clause 4.4; (f) introduce malicious code or conduct penetration testing or load testing without Breeze’s prior written consent; or (g) use the Services in a manner that impairs their availability or integrity for other users.

6.3The Customer acknowledges that the accuracy of the data it submits determines the validity of the output. Breeze structures, verifies, transmits and preserves what the Customer supplies; it does not independently confirm the commercial truth of the underlying transaction.

6.4Breeze may suspend an Authorised User’s access immediately, without prior notice, where Breeze reasonably suspects a breach of clause 6.2, and shall notify the Customer promptly thereafter with reasons so far as it is lawfully able to do so.

07

Third party dependencies and interoperating systems

7.1The Customer acknowledges that certain functions of the Platform depend on Third Party Dependencies which are not within Breeze’s control, including the MBS for invoice clearance, PAPSS and banking systems for settlement, distributed ledger networks for record anchoring, and identity, credit and sanctions data providers for screening.

7.2Breeze shall: (a) select Third Party Dependencies with reasonable skill and care; (b) maintain, so far as commercially available to it, contractual arrangements with those providers appropriate to the criticality of the dependency; (c) design the Services to queue, retry and preserve instructions during a Third Party Dependency outage so far as technically feasible; and (d) notify the Customer without undue delay of any Third Party Dependency outage which is materially affecting the Services, with periodic updates until it is resolved.

7.3Breeze is not liable for, and unavailability of a Third Party Dependency is Excluded Downtime in respect of, any failure of a Third Party Dependency itself. Breeze remains liable for its own failure to queue, retry, preserve or retransmit in accordance with clause 7.2(c) and Schedule 5.

7.4Breeze shall use reasonable endeavours to give the Customer not less than thirty (30) days notice of the intended replacement or removal of a material Third Party Dependency, together with a description of the effect on the Services.

08

Availability commitment

8.1Breeze shall make each subscribed Module available, in each Measurement Period, at not less than the Availability Target stated for that Module and the Customer’s Service Tier in Schedule 2.

8.2A Module is “Available” when an Authorised User with valid credentials and a functioning internet connection can log in to the dashboard for that Module and perform its core functions, and when the corresponding API endpoints return valid responses to correctly formed requests.

8.3Availability is calculated for each Module separately, in each Measurement Period, as: Availability (%) = [(T minus E minus D) divided by (T minus E)] multiplied by 100, where T is the total number of minutes in the Measurement Period, E is the total number of minutes of Excluded Downtime, and D is the total number of minutes of Downtime.

8.4Availability is measured by Breeze’s monitoring systems at the public API gateway and dashboard entry points, sampled at intervals of not more than sixty (60) seconds. Those records are the primary evidence of Availability. The Customer may request the underlying measurement data for any Measurement Period, and Breeze shall provide it within ten (10) Business Days.

8.5The following are Excluded Downtime and are disregarded in the calculation of Availability:

(a)scheduled maintenance carried out in accordance with clause 10.1;

(b)emergency maintenance carried out in accordance with clause 10.3, capped at four (4) hours in any Measurement Period for the purpose of this exclusion;

(c)unavailability of a Third Party Dependency, save to the extent caused by Breeze’s own act or omission;

(d)failures caused by the Customer’s own systems, network, configuration, integration code, credentials or misuse, or by the Customer’s failure to implement a mandatory update notified under clause 10.5;

(e)a Force Majeure Event;

(f)suspension of the Services lawfully effected under clause 21 or clause 28;

(g)use of features designated as beta, pilot, preview or trial; and

(h)unavailability during a period in which the Customer has requested that Breeze suspend or throttle the Services.

8.6Breeze shall also meet the performance targets stated in Part B of Schedule 2. A failure to meet a performance target does not itself give rise to a Service Credit, but persistent failure over three (3) consecutive Measurement Periods entitles the Customer to escalate under clause 12.3 and to require a remediation plan.

09

Support services and incident management

9.1Breeze shall operate a support desk reachable by the channels, and during the hours, stated for the Customer’s Service Tier in Schedule 3. Enterprise tier Customers shall additionally be assigned a named service manager and a documented escalation contact list.

9.2On receipt of a reported Incident, Breeze shall assign a Severity Level in accordance with the classification matrix in Schedule 3, acting reasonably and having regard to the operational and financial impact on the Customer. Where the Customer disagrees with the assigned Severity Level, the matter shall be escalated immediately under clause 9.6 and Breeze shall treat the Incident at the higher of the two classifications until the escalation is determined.

9.3Breeze shall meet the Response, update, Workaround and Resolution targets stated in Schedule 3 for the assigned Severity Level. Time runs from the time the Incident is first reported to the support desk or first detected by Breeze’s monitoring, whichever is earlier.

9.4The Customer shall provide the information reasonably necessary to reproduce and diagnose an Incident, including transaction or document references, timestamps, error messages, screenshots and, where relevant, API request and response payloads. Where Breeze is waiting on information reasonably requested from the Customer, the Response and Resolution clocks are suspended, provided that Breeze has clearly identified the information required and the fact that the clock is suspended.

9.5Breeze shall maintain a record of all Incidents, including the time of report, Severity Level, actions taken, time of Workaround and time of Resolution, and shall make that record available to the Customer on request.

9.6The escalation path in Part C of Schedule 3 applies where a Response, Workaround or Resolution target is missed, where an Incident recurs, or where the Customer disputes a Severity Level. Escalation does not relieve Breeze of any Service Level obligation.

9.7For any P1 Incident, Breeze shall provide a written root cause analysis to the Customer within five (5) Business Days of Resolution, identifying the cause, the corrective action taken and the preventive measures adopted.

9.8Support does not include: (a) support of the Customer’s own hardware, network or third party software; (b) development of bespoke integration code for the Customer; (c) data entry or transaction processing on the Customer’s behalf; or (d) training beyond the standard onboarding and Documentation, each of which may be provided as chargeable professional services.

10

Maintenance, changes and releases

10.1Scheduled maintenance shall be carried out within the maintenance window of 00:00 to 04:00 Gulf Standard Time on Sundays, or such other window as the Parties agree in writing. Breeze shall give not less than five (5) Business Days notice of scheduled maintenance and shall not carry out more than eight (8) hours of scheduled maintenance in any Measurement Period.

10.2Breeze shall use reasonable endeavours to avoid scheduled maintenance during any period notified by the Customer in advance as a critical business period, such as a statutory tax filing deadline or a documentary credit expiry date.

10.3Breeze may carry out emergency maintenance at any time where necessary to preserve the security, integrity or continued operation of the Platform. Breeze shall give as much notice as is reasonably practicable, shall confine the work to what is necessary, and shall provide a written explanation to the Customer within two (2) Business Days.

10.4Breeze may enhance, modify or replace features of the Platform, provided that no such change materially reduces the functionality subscribed for by the Customer during the then current Subscription Term without the Customer’s consent.

10.5Where a change requires action by the Customer, including an update to integration code, Breeze shall give not less than thirty (30) days notice, or such longer period as is reasonable having regard to the scale of the change. Breeze shall give not less than six (6) months notice of the deprecation of any published API version, and shall continue to support the immediately preceding major API version for not less than twelve (12) months after the release of its successor.

10.6Where a change is mandated by Applicable Law, by a regulator, or by an operator of a Third Party Dependency such as the NRS in respect of the MBS, Breeze shall implement it within the period required and shall notify the Customer as soon as reasonably practicable, together with a description of any action the Customer must take.

11

Business continuity, disaster recovery and data backup

11.1Breeze shall maintain, test and keep current a documented business continuity and disaster recovery plan proportionate to the criticality of the Services, and shall provide a summary of that plan to the Customer on request.

11.2Breeze shall design the Services to meet a recovery time objective of four (4) hours and a recovery point objective of fifteen (15) minutes in respect of transaction and document records, measured from the declaration of a disaster.

11.3Breeze shall take encrypted backups of Customer Data not less than once every twenty four (24) hours, shall replicate data to a geographically separate availability region, and shall retain backups for not less than thirty five (35) days.

11.4Breeze shall test its disaster recovery arrangements not less than once in every twelve (12) months and shall provide a summary of the test results to Enterprise tier Customers within twenty (20) Business Days of completion.

11.5Records anchored cryptographically under BridgeOS shall remain independently verifiable following any recovery event, and Breeze shall preserve the integrity of the audit trail across recovery.

12

Service level reporting and governance

12.1Breeze shall provide the Customer with a service report within ten (10) Business Days after the end of each Measurement Period, containing: (a) achieved Availability for each subscribed Module against the Availability Target; (b) a summary of Incidents by Severity Level with Response and Resolution times; (c) details of Downtime and Excluded Downtime; (d) any Service Credits accrued; (e) scheduled and emergency maintenance carried out; and (f) any security incident notified in the period.

12.2Reporting is provided monthly to Enterprise tier Customers, quarterly to Professional tier Customers, and on request to Essential tier Customers.

12.3The Parties shall hold a service review meeting quarterly, or at such other frequency as the Order Form states, to review Service Level performance, open Incidents, remediation plans, forthcoming changes and the roadmap. Either Party may convene an additional review meeting on ten (10) Business Days notice where Service Levels have not been met.

12.4The Parties shall review this Agreement and the Service Levels not less than once every twelve (12) months and shall consider in good faith any adjustment justified by changes in the Customer’s volumes, the Modules subscribed, or Applicable Law.

13

Service credits and chronic failure

13.1Where Breeze fails to meet an Availability Target for a Module in a Measurement Period, the Customer is entitled to a Service Credit calculated in accordance with Part C of Schedule 2 by reference to the Fees payable for that Module in that Measurement Period.

13.2The Customer shall claim a Service Credit in writing within thirty (30) days after the end of the Measurement Period in which the failure occurred, identifying the Module and the failure claimed. Breeze shall determine the claim within ten (10) Business Days and shall apply any Service Credit against the next invoice issued to the Customer, or, where no further invoice is to be issued, shall pay it within thirty (30) days.

13.3Service Credits in any Measurement Period shall not in aggregate exceed thirty per cent (30%) of the Fees payable for the affected Module in that Measurement Period.

13.4Save in the case of fraud, wilful misconduct or Chronic Failure, Service Credits are the Customer’s sole financial remedy for a failure to meet an Availability Target. This clause does not limit any right of the Customer to claim in respect of a breach of any other obligation under this Agreement, including breach of clause 14 (Information Security) or clause 15 (Data Protection).

13.5A “Chronic Failure” occurs where Breeze fails to meet the Availability Target for the same Module in three (3) consecutive Measurement Periods, or in any four (4) Measurement Periods within a rolling period of twelve (12) months.

13.6On a Chronic Failure, the Customer may, without prejudice to its other rights: (a) require Breeze to produce a written remediation plan within ten (10) Business Days and to implement it at Breeze’s cost; and (b) terminate the affected Module, or, where the affected Module is material to the Customer’s use of the Platform as a whole, this Agreement, on thirty (30) days written notice, without early termination charge and with a pro rata refund of Fees prepaid for the unexpired period.

14

Information security

14.1Breeze shall implement and maintain an information security management system aligned to ISO/IEC 27001 and shall apply, as a minimum, the technical and organisational measures set out in Part A of Schedule 4.

14.2Breeze shall encrypt Customer Data in transit using TLS 1.2 or higher and at rest using AES 256 or an equivalent or stronger standard, shall enforce multi factor authentication for administrative access, shall apply role based access control on the principle of least privilege, and shall maintain immutable audit logging of all access to and actions on Customer Data.

14.3Breeze shall commission an independent penetration test of the Platform not less than once in every twelve (12) months, and shall make an executive summary of the findings and the remediation status available to the Customer on request, subject to clause 17.

14.4Breeze shall remediate identified vulnerabilities within the following periods from identification: critical, seven (7) days; high, thirty (30) days; medium, ninety (90) days; low, at the next scheduled release. Where a remediation period cannot be met, Breeze shall notify the Customer, implement compensating controls and provide a remediation timetable.

14.5Breeze shall notify the Customer of any security incident affecting or reasonably likely to affect Customer Data without undue delay and in any event within twenty four (24) hours of becoming aware of it, and shall provide: the nature and scope of the incident, the categories and volume of data affected, the likely consequences, the measures taken or proposed, and a point of contact. Breeze shall provide updates as the investigation progresses and a final written report within fifteen (15) Business Days of containment.

14.6Breeze shall not be required to await the conclusion of its investigation before notifying under clause 14.5, and shall not condition notification on a determination of fault.

14.7The Customer may, on thirty (30) days written notice and not more than once in any twelve (12) month period, audit Breeze’s compliance with clauses 14 and 15, at the Customer’s cost, during business hours, without disrupting Breeze’s operations, and subject to the auditor executing confidentiality undertakings. Breeze may satisfy an audit request by providing a current independent third party assurance report covering the matters in scope. A regulator of the Customer, and any person appointed by it, may exercise audit and access rights to the extent required by Applicable Law, without the frequency and cost restrictions in this clause.

14.8Breeze shall maintain the digital certificates, cryptographic keys and signing infrastructure used to sign, stamp and anchor documents, shall renew them before expiry, and shall operate documented key management and key rotation procedures.

15

Data protection

15.1Each Party shall comply with the data protection laws applicable to it in the performance of this Agreement, including the NDPA where the processing relates to a data subject in Nigeria.

15.2For the purposes of Customer Data submitted to the Platform by or on behalf of the Customer, the Customer is the data controller and Breeze is the data processor. For account administration, billing, security monitoring, regulatory reporting and its own anti money laundering obligations, Breeze acts as an independent data controller.

15.3The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects are set out in Part B of Schedule 4.

15.4As processor, Breeze shall: (a) process Personal Data only on the Customer’s documented instructions, including this Agreement, unless required to do otherwise by Applicable Law, in which case Breeze shall inform the Customer before processing unless prohibited from doing so; (b) ensure that persons authorised to process Personal Data are subject to a binding duty of confidentiality; (c) implement the measures described in clause 14 and Schedule 4; (d) assist the Customer, taking into account the nature of the processing, in responding to data subject requests and in carrying out data protection impact assessments; (e) notify the Customer of any personal data breach in accordance with clause 14.5; and (f) at the Customer’s election, delete or return Personal Data on expiry or termination in accordance with clause 30.

15.5The Parties record the following statutory provisions as the framework governing the processing under this Agreement:

(a)Section 39 of the Nigeria Data Protection Act 2023: a data controller and a data processor shall each implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of Personal Data in its possession or under its control, including, where appropriate, pseudonymisation, encryption and periodic assessment of risks to processing systems.

(b)Section 40(1) of the Nigeria Data Protection Act 2023: where a personal data breach occurs in respect of Personal Data being stored or processed by a data processor, the processor shall, on becoming aware of the breach, notify the data controller that engaged it, describing the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned, and shall respond to all information requests from that controller.

(c)Section 40(2) of the Nigeria Data Protection Act 2023: a data controller shall, within seventy two (72) hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals, notify the Nigeria Data Protection Commission of the breach. The Customer, as controller, is responsible for that notification, and Breeze shall provide the information and assistance reasonably required to enable it to be made within time.

(d)Section 40(3) of the Nigeria Data Protection Act 2023: where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the data controller shall communicate the breach to the affected data subject, together with the measures the data subject may take to mitigate its effects.

(e)Sections 41 to 43 of the Nigeria Data Protection Act 2023: Personal Data may be transferred out of Nigeria only where the recipient jurisdiction, sector, international organisation or recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording an adequate level of protection, or where one of the listed derogations applies, including the data subject’s informed consent and necessity for the performance of a contract to which the data subject is party.

15.6The Customer authorises Breeze to appoint the sub processors listed in Part C of Schedule 4. Breeze shall impose on each sub processor data protection obligations no less protective than those in this clause 15 and shall remain liable for the acts and omissions of its sub processors as for its own. Breeze shall give the Customer not less than thirty (30) days notice of the intended appointment or replacement of a sub processor. If the Customer reasonably objects on data protection grounds within that period, the Parties shall discuss in good faith, and if no resolution is reached the Customer may terminate the affected Module without penalty and with a pro rata refund.

15.7The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all notices and obtained all consents required, and that its instructions do not cause Breeze to breach Applicable Law.

15.8Breeze shall notify the Customer promptly if, in its opinion, an instruction from the Customer infringes Applicable Law, and may suspend performance of that instruction pending resolution.

15.9The hosting locations for Customer Data are stated in Part D of Schedule 4. Where the Customer subscribes for the Vault NRS E-Invoice Module, invoice data and associated Personal Data relating to Nigerian taxpayers shall be hosted and archived in accordance with paragraph 7 of Schedule 5. Breeze shall not transfer Customer Data to a jurisdiction other than those stated without the Customer’s prior written consent and a lawful transfer mechanism.

16

Customer data, records and document integrity

16.1As between the Parties, all right, title and interest in Customer Data remains vested in the Customer. The Customer grants Breeze a non-exclusive licence to host, copy, transmit, process and display Customer Data to the extent necessary to provide the Services and to comply with Applicable Law.

16.2Breeze shall preserve the integrity of Trade Documents, shall maintain a cryptographic and immutable audit trail of every creation, amendment, signature, verification, transfer and transmission event, and shall make that audit trail available to the Customer through the Platform and by export.

16.3Breeze shall retain Customer Data for the retention period stated in the Order Form or, where none is stated, for the longer of the Subscription Term and any statutory retention period applicable to the record. In respect of records cleared through the MBS, the retention period in paragraph 7 of Schedule 5 applies.

16.4Breeze may use anonymised and aggregated data derived from use of the Platform, from which the Customer, its counterparties and any data subject cannot be identified, for the purposes of security, capacity planning, benchmarking and improvement of the Services. Breeze shall not disclose Customer Data or transaction level data to any other customer, financier or third party except as instructed by the Customer, as necessary to perform an instruction given through the Platform, or as required by Applicable Law.

16.5The Customer may export its Customer Data and audit trails through the Platform at any time during the Subscription Term at no additional charge, in the machine readable formats supported by Breeze.

17

Confidentiality

17.1“Confidential Information” means all information disclosed by one Party to the other, whether before or after the Effective Date, which is identified as confidential or which by its nature ought reasonably to be treated as confidential, including the Platform architecture, security measures, pricing, Customer Data, counterparty details, transaction terms and the contents of this Agreement.

17.2The receiving Party shall keep Confidential Information confidential, use it only for the purposes of this Agreement, and disclose it only to those of its officers, employees, professional advisers, auditors, insurers, financiers and subcontractors who need to know it and who are bound by equivalent obligations.

17.3Clause 17.2 does not apply to information which: (a) is or becomes public through no breach of this Agreement; (b) was lawfully in the receiving Party’s possession free of restriction before disclosure; (c) is lawfully received from a third party free of restriction; or (d) is independently developed without use of the Confidential Information.

17.4A Party may disclose Confidential Information to the extent required by Applicable Law, by a court of competent jurisdiction, or by a regulator, tax authority or stock exchange, provided that, where lawful and practicable, it gives the other Party prior notice and a reasonable opportunity to seek protective measures.

17.5The obligations in this clause survive termination for a period of five (5) years, and indefinitely in respect of trade secrets and Personal Data.

17.6Neither Party shall use the other’s name, logo or marks in any publicity, marketing or reference without prior written consent, save that Breeze may include the Customer’s name and logo in a list of customers, and in submissions to regulators and accreditation bodies, with the Customer’s prior written consent, which shall not be unreasonably withheld.

18

Regulatory compliance, financial crime and sanctions

18.1Each Party shall comply with all Applicable Law relating to anti money laundering, countering the financing of terrorism, anti bribery and corruption, tax reporting, export control and economic sanctions administered by the United Nations, the Federal Republic of Nigeria, the United States of America, the United Kingdom and the European Union.

18.2The Customer represents on the Effective Date and on each day of the Term that neither it, nor any of its directors, beneficial owners, Authorised Users or counterparties in a transaction processed through the Platform, is a sanctioned person or is owned or controlled by a sanctioned person.

18.3Breeze may screen Customer Data and counterparty data against sanctions, politically exposed person and adverse media sources through Radar, and may refuse, block, delay, freeze or report any transaction, document or instruction where required by Applicable Law or where Breeze reasonably suspects financial crime. Breeze shall not be liable for any loss arising from action lawfully taken under this clause, and shall notify the Customer to the extent it is lawfully permitted to do so.

18.4The Customer acknowledges that Radar outputs, risk scores and compliance passports are decision support tools. The Customer remains solely responsible for discharging its own regulatory obligations and for the decisions it takes, and shall not rely on Radar as a substitute for its own compliance programme.

18.5Where Breeze holds any licence, accreditation or registration necessary to provide a Module, including accreditation in respect of the MBS, Breeze shall maintain it in good standing throughout the Term and shall notify the Customer within two (2) Business Days of any suspension, revocation, material variation or regulatory direction affecting it.

19

Legal effect of electronic records and signatures

19.1The Parties intend that documents created, signed, transferred and stored through the Platform shall have the legal effect of their paper equivalents, to the fullest extent permitted by the law governing the document concerned.

19.2Breeze shall operate the Platform so as to satisfy, in respect of electronic transferable records, the reliability, singularity, integrity and exclusive control requirements of the MLETR and of any enactment of it applicable to a document, and shall support presentation and examination under the eUCP and the eURC.

19.3The Parties record the following provisions as material to the legal effect of records generated through the Platform in Nigeria:

(a)Section 84 of the Evidence Act 2011: a statement contained in a document produced by a computer is admissible as evidence of any fact stated in it where the conditions as to regular use of the computer, supply of the information in the ordinary course of activities, proper operation of the computer, and derivation of the information from that supplied are satisfied, and where a certificate identifying the document and describing the manner of its production is produced.

(b)Section 17 of the Cybercrimes (Prohibition, Prevention, etc.) Act 2015: electronic signatures in respect of purchases of goods and any other transactions are binding, and where a rule of evidence requires a signature, that requirement is met by an electronic signature.

(c)The UNCITRAL Model Law on Electronic Transferable Records 2017: an electronic record satisfies a requirement for a transferable document or instrument where a reliable method is used to identify it as the electronic transferable record, to render it capable of being subject to control from its creation until it ceases to have effect, and to retain its integrity.

19.4Neither Party shall dispute the validity, enforceability or admissibility of a record generated through the Platform on the sole ground that it is in electronic form or that it was signed electronically.

19.5Breeze does not warrant that any particular bank, counterparty, customs authority, court or other third party will accept an electronic document, where acceptance depends on that third party’s own policy or on the law of a jurisdiction that has not enacted the MLETR or an equivalent.

20

Fees, invoicing and taxes

20.1The Customer shall pay the Fees stated in the Order Form and calculated in accordance with Schedule 6, without deduction, set off or counterclaim save as expressly permitted by this Agreement.

20.2Recurring Fees are invoiced in advance and transaction based Fees are invoiced monthly in arrears, in each case payable within thirty (30) days of the date of a valid invoice, unless the Order Form states otherwise.

20.3All Fees are exclusive of value added tax and any other applicable indirect tax, which shall be added at the prevailing rate and paid by the Customer.

20.4Where the Customer is required by Applicable Law to deduct withholding tax from a payment, the Customer shall account for that tax to the relevant authority, shall provide Breeze with a valid withholding tax credit note or equivalent evidence within thirty (30) days of the deduction, and shall be entitled to remit the net amount. The Customer shall cooperate reasonably with Breeze in claiming any relief available under an applicable double taxation treaty.

20.5Breeze may increase recurring Fees once in any twelve (12) month period, with effect from the start of a renewal Subscription Term, on not less than sixty (60) days written notice. If the increase exceeds ten per cent (10%), the Customer may terminate the affected Module by notice given before the increase takes effect.

20.6Fees paid are non-refundable except where an express provision of this Agreement provides for a refund.

20.7The Customer shall notify Breeze of any disputed invoice within fifteen (15) Business Days of receipt, stating the grounds. The Customer shall pay the undisputed portion when due. The Parties shall resolve the disputed portion under clause 32, and the disputed portion shall not be treated as overdue while the dispute is being pursued in good faith.

20.8Overdue amounts bear interest at the rate of one and one half per cent (1.5%) per month, or the maximum rate permitted by Applicable Law if lower, accruing daily from the due date until payment.

21

Suspension for non-payment

21.1Where an undisputed invoice remains unpaid for more than fifteen (15) Business Days after the due date, Breeze may, on giving not less than ten (10) Business Days written notice, suspend the Customer’s access to the Services until payment is made in full.

21.2During any suspension under this clause: (a) the Customer remains liable for recurring Fees; (b) Breeze shall continue to preserve Customer Data and shall not delete it; (c) Breeze shall continue to complete or safely terminate any transaction already in flight, including any invoice already transmitted for clearance and any documentary credit already issued; and (d) the Customer shall retain read only access to its records for the purpose of regulatory and tax compliance.

21.3Breeze shall restore access within one (1) Business Day of receipt of payment in cleared funds.

22

Warranties

22.1Each Party warrants that it has full power and authority to enter into and perform this Agreement, that it holds all licences and authorisations necessary to do so, and that this Agreement constitutes its binding obligations.

22.2Breeze warrants that: (a) the Services will perform materially in accordance with the Documentation; (b) it will provide the Services with reasonable skill and care and in accordance with the Service Levels; (c) it owns or is licensed to use all Intellectual Property Rights necessary to provide the Services; (d) it will not knowingly introduce malicious code into the Platform and will use industry standard tools to prevent it; and (e) it holds and will maintain the accreditations stated in the Order Form.

22.3The Customer warrants that: (a) the Customer Data it submits is accurate, complete and lawfully obtained; (b) its use of the Services complies with Applicable Law; (c) the underlying trade, tax or financing transaction to which any Trade Document relates is genuine; and (d) it has not previously financed, assigned or encumbered any receivable submitted for financing through Accelerate.

22.4Except as expressly stated in this Agreement, all warranties, conditions and terms implied by statute or common law are excluded to the fullest extent permitted by Applicable Law.

23

Nature of the services and disclaimers

23.1Breeze is a technology provider. Breeze is not a bank, deposit taking institution, insurer, insurance broker, securities dealer, customs agent, tax adviser or legal adviser, and nothing in this Agreement constitutes financial, investment, tax, insurance or legal advice.

23.2Breeze does not: (a) assume any payment, credit, guarantee or settlement obligation in respect of any transaction executed through the Platform; (b) warrant that any financier will make, or maintain, an offer through Accelerate, or that any offer will be on particular terms; (c) underwrite any insurance risk, Threshold operating as a technology and intermediation layer between the Customer and the insurer of record; (d) warrant that any documentary credit, guarantee or collection will be honoured by an issuing, advising or confirming bank; or (e) warrant that any tax authority will clear, accept or refrain from querying any invoice.

23.3Where Breeze presents information generated by an automated, algorithmic or artificial intelligence assisted process, including discrepancy examination in Express and risk scoring in Radar, that output is provided to assist the Customer’s own review. It does not replace the independent judgement of the Customer or of any bank, and shall not be relied on as a determination of compliance, creditworthiness or legal effect.

23.4The Customer is responsible for the commercial decisions it takes in reliance on the Services, and for the tax positions, customs declarations and regulatory filings it makes.

24

Indemnities

24.1Breeze shall indemnify the Customer against all losses, damages, costs and reasonable legal expenses awarded against or reasonably settled by the Customer arising from a third party claim that the Customer’s permitted use of the Platform infringes that third party’s Intellectual Property Rights. This indemnity does not apply to a claim arising from Customer Data, from the Customer’s modification of the Services, or from use of the Services in combination with items not supplied by Breeze where the infringement would not have arisen but for that combination.

24.2Where a claim under clause 24.1 arises or is reasonably likely to arise, Breeze may at its option and cost procure the right for the Customer to continue using the affected element, replace or modify it so that it is non-infringing without material loss of functionality, or, if neither is achievable on commercially reasonable terms, terminate the affected Module and refund Fees prepaid for the unexpired period.

24.3The Customer shall indemnify Breeze against all losses, damages, costs and reasonable legal expenses arising from: (a) any breach by the Customer of clause 6.2; (b) any claim by a third party, including a bank, financier, insurer, counterparty or tax authority, arising from the inaccuracy, incompleteness or unlawfulness of Customer Data; (c) any claim arising from the underlying trade, tax or financing transaction to which a Trade Document relates; and (d) any claim by an Authorised User or an end user under clause 4.4 arising from the Customer’s own acts or omissions.

24.4A Party seeking to rely on an indemnity shall notify the other promptly of the claim, shall not admit liability or settle without the indemnifying Party’s consent (not to be unreasonably withheld), shall allow the indemnifying Party to conduct the defence, and shall provide reasonable assistance at the indemnifying Party’s cost.

25

Limitation of liability

25.1Nothing in this Agreement limits or excludes either Party’s liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) wilful misconduct; (d) the Customer’s obligation to pay Fees properly due; or (e) any liability which cannot lawfully be limited or excluded.

25.2Subject to clause 25.1, neither Party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any: loss of profit; loss of revenue; loss of anticipated savings; loss of business or business opportunity; loss of goodwill or reputation; loss of or failure to obtain financing; or any indirect or consequential loss.

25.3Subject to clauses 25.1 and 25.4, the total aggregate liability of Breeze arising out of or in connection with this Agreement in any period of twelve (12) months shall not exceed the greater of: (a) the total Fees paid and payable by the Customer under this Agreement in the twelve (12) months immediately preceding the first event giving rise to liability; and (b) United States Dollars fifty thousand (US$50,000).

25.4The limit in clause 25.3 is replaced by a limit equal to the greater of one hundred and fifty per cent (150%) of the Fees paid and payable in the preceding twelve (12) months and United States Dollars one hundred and fifty thousand (US$150,000) in respect of liability arising from: (a) breach of clause 17 (Confidentiality); (b) breach of clause 14 (Information Security) or clause 15 (Data Protection); and (c) the indemnity in clause 24.1.

25.5Each provision of this clause 25 operates separately. If any part is held unenforceable, the remaining parts continue in effect.

25.6The Customer shall take reasonable steps to mitigate its loss, including maintaining reasonable contingency arrangements for the periods during which the Services may be unavailable in accordance with this Agreement.

26

Insurance

26.1Breeze shall maintain, with reputable insurers, professional indemnity and cyber liability insurance appropriate to the nature and scale of the Services, with a limit of indemnity of not less than United States Dollars one million (US$1,000,000) in the aggregate, and shall provide evidence of cover to the Customer on reasonable request.

27

Force majeure

27.1A “Force Majeure Event” means an event beyond the reasonable control of the affected Party, including act of God, flood, fire, epidemic or pandemic, war, terrorism, civil disturbance, industrial action not involving that Party’s own workforce, act of government or regulator, nationwide or regional failure of telecommunications, power or internet infrastructure, and cyber attack of a nature and scale that could not have been prevented by the security measures required under this Agreement.

27.2Neither Party is liable for a failure or delay in performance caused by a Force Majeure Event, provided that the affected Party notifies the other as soon as reasonably practicable, uses reasonable endeavours to mitigate the effect and to resume performance, and invokes its business continuity arrangements.

27.3A Force Majeure Event does not excuse the Customer’s obligation to pay Fees already accrued.

27.4If a Force Majeure Event continues for more than thirty (30) consecutive days, either Party may terminate the affected Module or this Agreement on fifteen (15) days written notice, and Breeze shall refund Fees prepaid for the unexpired period.

28

Suspension

28.1Breeze may suspend the Services, in whole or in part, immediately on notice where: (a) required by Applicable Law or by a regulator; (b) necessary to address a material security threat to the Platform or to Customer Data; (c) Breeze reasonably suspects a breach of clause 6.2 or clause 18; or (d) permitted under clause 21.

28.2Breeze shall confine any suspension to what is necessary, shall restore the Services as soon as the cause has been resolved, and shall keep the Customer informed so far as it is lawfully able to do so.

28.3Suspension under clause 28.1(b) is Excluded Downtime only where the threat did not arise from Breeze’s failure to comply with clause 14.

29

Termination

29.1Either Party may terminate this Agreement or any affected Module immediately on written notice where the other Party: (a) commits a material breach which is incapable of remedy; (b) commits a material breach which is capable of remedy and fails to remedy it within thirty (30) days of written notice specifying the breach and requiring its remedy; (c) suffers an insolvency event, including the appointment of a receiver, administrator or liquidator, a composition with creditors, or the cessation of all or a substantial part of its business; or (d) is unable lawfully to continue to perform this Agreement.

29.2The Customer may terminate under clause 13.6 (Chronic Failure), clause 2.3 (material adverse update), clause 15.6 (sub processor objection), clause 20.5 (Fee increase) and clause 27.4 (prolonged Force Majeure Event).

29.3Breeze may terminate immediately on written notice where the Customer, an Authorised User or a beneficial owner becomes a sanctioned person, or where continued provision of the Services would in Breeze’s reasonable opinion cause Breeze to breach Applicable Law.

29.4Either Party may terminate this Agreement for convenience on ninety (90) days written notice, provided that any Subscription Term already commenced shall run to its end and Fees for that Subscription Term remain payable.

29.5Termination of one Module does not terminate the remainder of this Agreement unless the terminating Party states otherwise and the remaining Modules cannot reasonably be used without the terminated Module.

30

Consequences of termination and exit assistance

30.1On expiry or termination: (a) the Customer’s right to access the affected Modules ceases, subject to clause 30.2; (b) each Party shall return or destroy the other’s Confidential Information, save for copies required to be retained by Applicable Law or held in routine backup, which remain subject to clause 17; and (c) all Fees accrued to the date of termination become immediately due.

30.2Breeze shall provide an exit period of ninety (90) days from the effective date of termination, during which Breeze shall: (a) maintain the Customer’s read only access to its records and audit trails; (b) provide the Customer with a complete export of Customer Data, including Trade Documents, clearance evidence, signatures and audit trails, in a structured, commonly used and machine readable format; and (c) provide reasonable migration assistance, at Breeze’s standard professional services rates where the assistance goes beyond the standard export.

30.3Breeze shall complete or safely unwind any transaction in flight at the date of termination, including any documentary credit issued, any invoice transmitted for clearance and any financing arrangement concluded through Accelerate, and the relevant provisions of this Agreement continue to apply to that transaction until it is concluded.

30.4At the end of the exit period, Breeze shall delete Customer Data securely, save for records which Breeze is required by Applicable Law to retain, which shall be retained for the required period only, and shall certify deletion in writing on request.

30.5Clauses 1, 13.2, 15, 16.1, 16.3, 17, 19.4, 20, 23, 24, 25, 30, 31, 32, 33 and 34, and any provision which by its nature is intended to survive, continue in force after termination.

31

Intellectual property

31.1All Intellectual Property Rights in the Platform, BridgeOS, the Modules, the Documentation, the templates, the underlying models and all improvements to them are and remain vested in Breeze or its licensors. Nothing in this Agreement transfers any such right to the Customer.

31.2The Customer retains all Intellectual Property Rights in Customer Data and in its own trade marks and branding.

31.3Where the Customer provides feedback, suggestions or ideas relating to the Services, Breeze may use them without restriction or payment, provided that no Confidential Information or Customer Data is disclosed to a third party in doing so.

32

Dispute resolution

32.1The Parties shall attempt in good faith to resolve any dispute arising out of or in connection with this Agreement by negotiation between their respective operational managers within ten (10) Business Days of written notice of the dispute.

32.2If unresolved, the dispute shall be escalated to a senior executive of each Party, who shall meet within a further ten (10) Business Days.

32.3If the dispute remains unresolved twenty five (25) Business Days after the initial notice, it shall be referred to and finally resolved by arbitration.

32.4The arbitration shall be conducted under the arbitration law stated in the Order Form, by one (1) arbitrator, with the seat of arbitration as stated in the Order Form and the language of the arbitration being English. The award shall be final and binding.

32.5Where the dispute concerns the Vault NRS E-Invoice Module, paragraph 10 of Schedule 5 applies in place of clause 32.4.

32.6Nothing in this clause prevents a Party from seeking urgent injunctive or other interim relief from a court of competent jurisdiction, or from taking any step required to preserve a limitation period or to comply with a regulatory direction.

32.7The Parties shall continue to perform their obligations under this Agreement while a dispute is being resolved.

33

Governing law and jurisdiction

33.1This Agreement and any dispute or claim arising out of or in connection with it, including any non-contractual obligation, is governed by and shall be construed in accordance with the laws of the Federal Republic of Nigeria.

33.2Clause 33.1 is subject to any mandatory provision of the law of the Customer’s jurisdiction which cannot be excluded by agreement, and to paragraph 10 of Schedule 5 in respect of the Vault NRS E-Invoice Module.

34

Notices

34.1A notice under this Agreement shall be in writing and shall be delivered by hand, by internationally recognised courier, or by email to the address stated in the Order Form or such other address as a Party notifies.

34.2A notice is deemed received: on delivery, if delivered by hand during business hours; on the second Business Day after despatch, if sent by courier; and at the time of transmission, if sent by email during business hours in the place of receipt, and otherwise at 09:00 on the next Business Day, provided no automated non-delivery message is received.

34.3Operational communications, including Incident reports, maintenance notices and service reports, may be given through the Platform or by email to the operational contacts stated in the Order Form, and do not require the formality of clause 34.1.

34.4Notices of breach, suspension, termination or dispute shall not be given solely through the Platform.

35

General provisions

35.1Assignment. Neither Party may assign, transfer or charge this Agreement without the other’s prior written consent, not to be unreasonably withheld, save that Breeze may assign to an Affiliate or to a successor in connection with a merger, reorganisation or sale of substantially all of its assets, on notice to the Customer.

35.2Subcontracting. Breeze may subcontract the performance of any part of the Services but remains responsible for the acts and omissions of its subcontractors as for its own. Subcontracting involving Personal Data is governed by clause 15.6.

35.3Variation. No variation of this Agreement is effective unless in writing and signed by an authorised representative of each Party, save for updates made in accordance with clause 2.3.

35.4Waiver. No failure or delay in exercising a right is a waiver of it. A single or partial exercise does not preclude further exercise.

35.5Severance. If any provision is held invalid, illegal or unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, or if that is not possible, deleted, and the remainder of this Agreement shall continue in force.

35.6Entire agreement. This Agreement constitutes the entire agreement between the Parties in relation to its subject matter and supersedes all prior agreements, representations and understandings. Nothing in this clause limits liability for fraudulent misrepresentation.

35.7No partnership or agency. Nothing in this Agreement creates a partnership, joint venture, employment or agency relationship between the Parties. Neither Party may bind the other.

35.8Third party rights. Save for an Affiliate of Breeze exercising a right under clause 24 or clause 25, a person who is not a Party has no right to enforce any term of this Agreement.

35.9Counterparts and electronic execution. This Agreement may be executed in counterparts, each of which is an original and all of which together constitute one instrument. This Agreement may be executed electronically, and the Parties agree that an electronic signature applied through the Platform or through a recognised electronic signature service is binding.

35.10Language. This Agreement is made in the English language. Where a translation is prepared, the English version prevails.

36

Schedule 1 — Service description and module catalogue

Part A: BridgeOS core primitives

BridgeOS is the trust and execution layer on which every Module operates. It structures, verifies and executes trade transactions and provides the cryptographic audit trail referred to in clause 16.2.

PrimitiveFunctionOutput relied on by the Customer
OriginCreation of structured digital trade records from templates or submitted data, including invoices, purchase orders, bills of lading and negotiable instruments, in compliance with the MLETR.A structured, uniquely identified digital record capable of control and transfer.
VerifyReal time validation and authentication of trade documents, confirming integrity and detecting alteration or unauthorised modification.A verification result and cryptographic hash bound to the record.
FolderGrouping of related documents into a single transaction file, with shared audit trail, notes and status.A consolidated transaction file for financing, customs and audit purposes.
TransferExecution of ownership transfer, endorsement and approval workflows over a digital record.A recorded and time stamped change of control or approval.

Part B: Application layer Modules

ModuleDescription
ExpressDigital documentary credit and collections. Issuance, amendment, document examination, discrepancy identification and resolution, and settlement of letters of credit, usance letters of credit, bank guarantees and documentary collections, end to end, with connection to settlement rails including PAPSS.
VaultIntelligent document management. Template gallery, structured document generation, native electronic signature and stamping, folders, search, version history, permissions and immutable audit history. Includes the Vault NRS E-Invoice Module described in Schedule 5.
RadarCompliance and risk engine. Know your customer and know your business onboarding, issuance of verified business identity credentials, screening against sanctions and watchlists, counterparty risk scoring, duplicate financing detection and regulatory reporting.
AccelerateTrade finance marketplace. Listing of verified trade documents for financing, offer and counter offer negotiation, acceptance, and portfolio management, available on a white label basis for embedded deployment.
ThresholdInsurance layer. Risk priced coverage tied to individual transactions, arranged with the insurer of record, with Breeze operating as the technology and intermediation layer only.
TerminalWorkflow orchestration. End to end coordination of a trade transaction across Modules, counterparties, approvals and milestones.

Part C: Access channels

  • The Bridge dashboard, accessible through supported web browsers.
  • The Bridge public API, for programmatic access to every Module, on the basis described in the Documentation.
  • White label and embedded deployment, where subscribed, on the terms of clause 4.4.

The Modules subscribed by the Customer, and the Service Tier applicable to each, are stated in the Order Form. A Module not stated in the Order Form is not part of the Services.

37

Schedule 2 — Availability targets, performance targets and service credits

Part A: Availability targets by Module and Service Tier

Availability is calculated per Module per Measurement Period in accordance with clause 8.3.

Module or Module groupEssentialProfessionalEnterprise
Core Platform (dashboard, Origin, Verify, Folder, Transfer, Vault)99.0%99.5%99.9%
Express (documentary credit and collections)99.5%99.9%99.9%
Vault NRS E-Invoice (Breeze components only)99.5%99.5%99.9%
Radar (verification and screening)99.0%99.5%99.9%
Accelerate, Threshold and Terminal99.0%99.5%99.5%
Public API gateway99.5%99.9%99.9%

Part B: Performance targets

Measured over each Measurement Period, excluding periods of Excluded Downtime and excluding time attributable to a Third Party Dependency.

MeasureTarget
Median response time, synchronous API endpointsNot more than 500 milliseconds
95th percentile response time, synchronous API endpointsNot more than 1,500 milliseconds
Document generation from template to saved recordNot more than 30 seconds
Document verification result returnedNot more than 10 seconds
Invoice dispatch to the MBS after a valid instructionNot more than 60 seconds, excluding MBS processing time
Successful transaction rate, excluding validation rejectionsNot less than 99.5% of correctly formed requests

Part C: Service credits

Calculated as a percentage of the Fees payable for the affected Module in the Measurement Period in which the failure occurred, and claimed in accordance with clause 13.2. Service Credits in any Measurement Period are capped at thirty per cent (30%) of the Fees for the affected Module, in accordance with clause 13.3. Where a Module is provided at no charge, or is bundled without a separately identifiable Fee, the Service Credit is calculated against a notional Fee equal to the proportion of the total Fees attributable to that Module as stated in the Order Form.

Achieved Availability in the Measurement PeriodService Credit
Below the Availability Target but not less than 99.0%5% of the Fees for the affected Module
Below 99.0% but not less than 98.0%10% of the Fees for the affected Module
Below 98.0% but not less than 95.0%20% of the Fees for the affected Module
Below 95.0%30% of the Fees for the affected Module
38

Schedule 3 — Support model, severity classification and escalation

Part A: Support channels and hours

ItemEssentialProfessionalEnterprise
Support hoursBusiness HoursBusiness Hours, extended to 20:00 GST24 hours, 7 days, for P1 and P2
ChannelsEmail and in-platform ticketEmail, in-platform ticket, telephoneEmail, in-platform ticket, telephone, dedicated channel
Named service managerNoShared poolYes, named
Service reportingOn requestQuarterlyMonthly
Quarterly service reviewNoYesYes

Part B: Severity classification, response and resolution targets

LevelDefinitionResponseUpdate frequencyTarget Workaround and Resolution
P1 CriticalA Module is wholly unavailable, or data integrity is compromised, or a security incident affecting Customer Data has occurred, or settlement or clearance of a live transaction is blocked, with no Workaround.30 minutesHourlyWorkaround within 4 hours; Resolution within 8 hours
P2 HighA material function of a Module is unavailable or materially degraded, affecting multiple users or a live transaction, with no acceptable Workaround.2 Business HoursEvery 4 hoursWorkaround within 1 Business Day; Resolution within 3 Business Days
P3 MediumA function is impaired or performing incorrectly, but an acceptable Workaround exists and business operations continue.8 Business HoursDailyResolution within 10 Business Days
P4 LowCosmetic defect, documentation query, configuration request or enhancement request, with no operational impact.2 Business DaysWeeklyNext scheduled release

P1 targets apply on a 24 hours, 7 days basis for all Service Tiers. All other targets run during Business Hours for the applicable Service Tier.

Part C: Escalation matrix

StageBreeze contactTrigger
Level 1Support Engineer, support deskInitial report of any Incident.
Level 2Duty Service ManagerA Response or Workaround target is missed, or the Customer disputes a Severity Level.
Level 3Head of Engineering or Chief Technology OfficerA P1 Incident remains unresolved after 4 hours, or a P2 Incident after 2 Business Days.
Level 4Chief Operations OfficerA P1 Incident remains unresolved after 12 hours, or an Incident recurs three times in 30 days.
Level 5Chief Executive OfficerA Chronic Failure has occurred, or a remediation plan has not been delivered when due.

Contact names, telephone numbers and email addresses for each escalation level shall be stated in the Order Form and refreshed by Breeze within five (5) Business Days of any change.

39

Schedule 4 — Information security measures and data processing particulars

Part A: Technical and organisational security measures

Breeze shall implement and maintain, as a minimum, the following measures, which give effect to clause 14 and to section 39 of the Nigeria Data Protection Act 2023.

  • Governance: a documented information security policy set, an accountable security owner, an annual risk assessment, and an information security management system aligned to ISO/IEC 27001.
  • Access control: unique named accounts, multi factor authentication for all administrative and privileged access, role based access control applied on the principle of least privilege, quarterly access reviews, and immediate revocation on personnel departure.
  • Encryption: TLS 1.2 or higher for data in transit; AES 256 or stronger for data at rest; encryption of backups; hardware backed or equivalent key management with documented key rotation.
  • Document integrity: cryptographic hashing of every document version, immutable audit logging of creation, amendment, signature, verification and transfer events, and independent verifiability of the audit trail after any recovery event.
  • Network and infrastructure: segmented network architecture, managed firewalls, intrusion detection, denial of service protection, hardened builds, and separation of production, staging and development environments with no production data in non-production environments except where irreversibly anonymised.
  • Secure development: secure software development lifecycle, peer code review, static and dependency scanning in the build pipeline, and change control with segregation of duties between development and deployment.
  • Vulnerability management: continuous automated scanning, quarterly authenticated scans, annual independent penetration testing, and remediation within the periods in clause 14.4.
  • Logging and monitoring: centralised, tamper evident logging retained for not less than twelve (12) months, 24 hours a day security monitoring, and documented alerting thresholds.
  • Personnel: background screening appropriate to role and to Applicable Law, written confidentiality undertakings, security awareness training on joining and annually thereafter, and a documented joiners, movers and leavers process.
  • Physical security: hosting in facilities certified to ISO/IEC 27001 or an equivalent standard, with controlled access, environmental controls and continuous monitoring.
  • Resilience: the backup, replication and recovery arrangements in clause 11.
  • Incident management: a documented incident response plan, a defined severity scale, forensic readiness, and notification in accordance with clause 14.5.

Part B: Data processing particulars

ItemDetail
Subject matterProvision of the Services under this Agreement.
DurationThe Term, together with the exit period under clause 30.2 and any statutory retention period.
Nature and purposeCollection, structuring, storage, verification, signature, transmission, screening, retrieval, export and deletion of Customer Data, for the purpose of creating, managing, financing, clearing and settling trade and tax documentation.
Types of Personal DataIdentification data of directors, beneficial owners, signatories and Authorised Users, including name, position, contact details, identification numbers and signature images; transaction data in which individuals are named; screening results; access and audit logs.
Categories of data subjectsAuthorised Users; directors, officers and beneficial owners of the Customer and of its counterparties; signatories to Trade Documents; individual customers of the Customer where applicable.
Special categoriesNone is required for the Services. The Customer shall not submit special category data through the Platform.

Part C: Approved sub processors

Sub processorService providedProcessing location
Cloud hosting providerInfrastructure hosting and storageAs stated in the Order Form
Identity and sanctions data providerKYC, KYB and sanctions screening dataAs stated in the Order Form
Communications providerTransactional email and notificationsAs stated in the Order Form
Support platform providerSupport ticketing and service deskAs stated in the Order Form

Part D: Hosting and data residency

Category of dataPrimary hosting and residency
Platform data generallyThe primary region stated in the Order Form, with replication to the stated secondary region
Nigerian taxpayer invoice data and associated Personal DataHosted and archived in accordance with paragraph 7 of Schedule 5
BackupsEncrypted, held in a geographically separate availability region within the same residency perimeter
40

Schedule 5 — Vault NRS E-Invoice Module: Nigeria electronic invoicing terms

This Schedule applies only where the Customer subscribes for the Vault NRS E-Invoice Module. It prevails over the body of this Agreement to the extent of any inconsistency, in accordance with clause 2.2(b). Expressions defined in clause 1 have the same meaning in this Schedule.

1. Regulatory context and the role of the Parties

1.1Nigeria operates a continuous transaction control model of electronic invoicing. A supplier submits a business to business or business to government invoice to the NRS for clearance before it is issued to the buyer, and a cleared invoice carries an Invoice Reference Number and a cryptographic stamp. Business to consumer invoices are reported on a near real time basis. Invoices are exchanged in a structured format on the four corner model, being supplier, supplier access point, buyer access point and buyer.

1.2The Customer is at all times the taxpayer of record. Breeze acts solely as the technology provider through which the Customer creates, signs, transmits and archives its invoices, in the capacity stated in the Order Form.

1.3The following instruments constitute the regulatory framework for this Schedule:

(a)Nigeria Revenue Service (Establishment) Act 2025: establishes the Nigeria Revenue Service as the federal revenue authority, in succession to the Federal Inland Revenue Service, and confers on it the functions of assessment, collection and administration of federal revenue.

(b)Nigeria Tax Administration Act 2025: provides for the administration of taxes across Nigeria, including the deployment of electronic fiscal systems and the power of the Service to require taxable persons to issue invoices electronically in the prescribed structure and to transmit them for validation.

(c)National Regulatory Guideline for Electronic Invoicing in Nigeria 2025: prescribes the accreditation framework for Access Point Providers and System Integrators, the obligation to issue, install and renew digital certificates before expiry, the verification of authenticity and integrity of electronic invoices, and the standards of interoperability applicable to participants.

(d)Nigeria Data Protection Act 2023: governs the processing of Personal Data contained in invoice data, as set out in clause 15.5.

(e)Evidence Act 2011, section 84, and Cybercrimes (Prohibition, Prevention, etc.) Act 2015, section 17: govern the admissibility of computer generated records and the binding effect of electronic signatures, as set out in clause 19.3.

2. Breeze obligations

2.1Breeze shall generate each invoice in the structure prescribed by the NRS, capturing every mandatory field, including tax categories, payment means codes, line level discounts and charges, harmonised system codes, and supplier and buyer taxpayer identification numbers, at the point of creation.

2.2Breeze shall validate each invoice against the prescribed schema before transmission, shall reject or flag an invoice that fails validation, and shall return to the Customer a clear description of each validation error and the field to which it relates.

2.3Breeze shall digitally sign and transmit each valid invoice to the MBS for clearance, and shall return the Invoice Reference Number and cryptographic stamp onto the invoice record itself, so that the clearance evidence forms a permanent part of the document and its audit trail.

2.4Breeze shall apply and maintain the Customer’s native electronic signature on the invoice, being separate from and additional to the clearance stamp applied by the NRS, and shall record the signer name, position and signature image in the audit trail.

2.5Breeze shall maintain in good standing the accreditations, registrations and digital certificates required for it to transmit invoices to the MBS, shall renew each digital certificate before expiry, and shall operate documented certificate lifecycle management.

2.6Breeze shall make the same capability available through the Vault dashboard and through the documented API endpoint, and the resulting cleared invoice shall be identical in structure, signature and clearance status whichever channel is used.

2.7Breeze shall implement changes to the invoice schema, validation rules or transmission protocol notified by the NRS within the period required by the NRS, and shall notify the Customer of any action the Customer must take, in accordance with clause 10.6.

3. Customer obligations

3.1The Customer shall ensure the accuracy, completeness and timeliness of all invoice data, including its own and its counterparty’s taxpayer identification numbers, the tax classification of each line, the applicable rates, and the commercial substance of the transaction.

3.2The Customer shall submit invoices for clearance within the time required by Applicable Law and shall not use the Module to issue an invoice that does not correspond to a genuine supply.

3.3The Customer remains solely responsible for its tax positions, returns, filings, reconciliations and dealings with the NRS. Breeze does not file returns, does not compute the Customer’s tax liability and does not represent the Customer before the NRS.

3.4The Customer shall notify Breeze promptly of any change to its taxpayer status, turnover band, registration or enablement on the MBS self service portal that affects its ability to issue electronic invoices.

4. Module specific service levels

MeasureCommitment
Availability of the Breeze components of the ModuleAs stated in Part A of Schedule 2 for the applicable Service Tier
Validation result returned to the CustomerNot more than 10 seconds from submission
Dispatch of a valid invoice to the MBSNot more than 60 seconds from a valid instruction, excluding MBS processing time
Return of the Invoice Reference Number to the recordNot more than 60 seconds after receipt from the MBS
Retransmission of a queued invoice after an MBS outageAutomatic retry, commencing within 15 minutes of restoration of the MBS
Notification to the Customer of an MBS outage affecting clearanceWithin 60 minutes of Breeze becoming aware
Notification of accreditation or certificate status changeWithin 2 Business Days, in accordance with clause 18.5

5. Dependency on the Merchant Buyer Solution

5.1Clearance is an act of the NRS. Breeze does not warrant that any invoice will be cleared, and the rejection of an invoice by the NRS is not a failure of the Services.

5.2Unavailability of the MBS is a Third Party Dependency outage and is Excluded Downtime under clause 8.5(c).

5.3Breeze shall nevertheless, during any MBS outage: (a) accept, validate, sign and securely queue invoices submitted by the Customer; (b) preserve the submission sequence and time stamps; (c) retransmit automatically on restoration in accordance with paragraph 4; and (d) report to the Customer the status of every queued invoice. A failure by Breeze to do so is a failure of the Services and is not excused by the MBS outage.

6. Failure, correction and cancellation

6.1Where an invoice is rejected by the NRS, Breeze shall return the rejection reason to the Customer within the period stated in paragraph 4 and shall enable the Customer to correct and resubmit without re-keying data that was accepted.

6.2Correction, credit noting and cancellation of a cleared invoice shall be effected only by the mechanism permitted by the NRS. Breeze shall not delete or overwrite a cleared invoice, and every correction shall be recorded as a new version linked to the original in the audit trail.

7. Records, retention and residency

7.1Breeze shall archive each cleared invoice, together with its clearance evidence, signature and audit trail, in tamper evident form for not less than seven (7) years from the end of the tax year to which it relates, or such longer period as Applicable Law requires.

7.2Invoice data and associated Personal Data relating to Nigerian taxpayers shall be hosted and archived in the primary location stated in the Order Form, with any transfer outside Nigeria effected only on a lawful transfer basis under sections 41 to 43 of the Nigeria Data Protection Act 2023 and recorded in Part D of Schedule 4.

7.3Breeze shall provide the Customer with an export of its cleared invoices and clearance evidence, in a structured and machine readable format, at any time on request and on exit under clause 30.2.

8. Regulatory cooperation and audit

8.1Breeze shall cooperate with any request, inspection, audit or direction of the NRS, the National Information Technology Development Agency or the Nigeria Data Protection Commission relating to the Module, and shall notify the Customer of any such request affecting the Customer’s records, so far as it is lawfully permitted to do so.

8.2Breeze shall provide the Customer, on reasonable notice, with the records and evidence the Customer requires to respond to an NRS query, audit or assessment relating to invoices issued through the Module.

9. Loss or suspension of accreditation

9.1If Breeze’s accreditation or ability to transmit to the MBS is suspended, withdrawn or materially restricted, Breeze shall: (a) notify the Customer within two (2) Business Days; (b) continue to provide the remaining Vault functionality; (c) provide, at no charge, all assistance reasonably required for the Customer to migrate to an alternative accredited provider, including a complete export of invoice records; and (d) refund a pro rata share of the Fees attributable to the Module for the unexpired period.

9.2The Customer may terminate the Module immediately on notice in the circumstances described in paragraph 9.1, without early termination charge.

10. Governing law of this Schedule

10.1This Schedule, and any dispute arising out of or in connection with the Vault NRS E-Invoice Module, is governed by the laws of the Federal Republic of Nigeria.

10.2A dispute under this Schedule which is not resolved under clauses 32.1 and 32.2 shall be referred to and finally resolved by arbitration under the Arbitration and Mediation Act 2023, before a sole arbitrator appointed, in default of agreement, by the Chartered Institute of Arbitrators (UK) Nigeria Branch, with the seat of arbitration at Lagos, Nigeria and the language of the arbitration being English.

41

Schedule 6 — Fees and charges

The Fees applicable to the Customer are stated in the Order Form and are derived from the structure below. Where an item is not stated in the Order Form, no Fee is payable for it.

Part A: Recurring Fees

ItemBasis
Platform accessPer organisation, per annum or per month
Express licencePer institution, per annum
Vault document subscriptionPer user or per document band, per month
White label infrastructure licencePer deployment, per annum
Additional Authorised UsersPer user, per month

Part B: Transactional Fees

ItemBasis
Documentary credit processingPer issuance or amendment
Escrow processingPer instruction or per release
Radar verificationPer verification or per screening
NRS invoice clearancePer invoice transmitted for clearance
Document generation beyond the included allowancePer document
API calls beyond the included allowancePer thousand calls

Part C: Capital layer Fees

ItemBasis
AccelerateA spread or arrangement fee on financing concluded through the marketplace, as stated in the Order Form.
ThresholdA share of the insurance premium, as stated in the Order Form and as permitted by Applicable Law.

Part D: Professional services and other terms

  • Implementation, integration, migration, bespoke development and training are charged at the day rates stated in the Order Form.
  • Currency of invoicing: United States Dollars, Nigerian Naira, United Arab Emirates Dirham, or any other relevant currency as stated in the Order Form.
  • Payment terms: thirty (30) days from the date of a valid invoice, unless the Order Form states otherwise.
  • Taxes, withholding and interest on late payment are governed by clause 20.
42

Schedule 7 — Form of order form

Each Order Form is entered into under and incorporates this Agreement, and records the following for the Customer named in it.

FieldDetail
Order Form referenceStated in the Order Form
Customer legal nameStated in the Order Form
Registration or identification numberStated in the Order Form
Registered addressStated in the Order Form
Customer typeCorporate entity or individual
Jurisdiction of establishmentStated in the Order Form
Modules subscribedOrigin, Verify, Folder, Transfer, Express, Vault, Vault NRS E-Invoice, Radar, Accelerate, Threshold, Terminal
Service TierEssential, Professional or Enterprise
Deployment modelDirect, white label or embedded via API
Subscription commencement dateStated in the Order Form
Initial Subscription TermStated in the Order Form, in months
Pilot or proof of conceptYes, with the expiry date stated, or no
FeesAs set out in the attached pricing annex, derived from Schedule 6
Currency and payment termsStated in the Order Form
Included volumes and overageStated in the Order Form
Data retention periodStated in the Order Form, subject to clause 16.3 and paragraph 7 of Schedule 5
Hosting regionStated in the Order Form
Customer notice address and emailStated in the Order Form
Customer operational contactsNames, roles, telephone and email
Breeze escalation contacts (Levels 1 to 5)Names, roles, telephone and email
Service review frequencyMonthly, quarterly or on request
Special conditionsStated in the Order Form, naming the clause of this Agreement varied

Questions about these terms

If anything here is unclear, or you need an executed copy for your legal team, write to us and we will get back to you.