FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD All people, organizations, identifiers, legal conclusions, clinical parameters, and events are invented for text retrieval practice. Do not use as professional advice, an authoritative standard, a real filing, or an operational instruction. RECORD 2: ENTERPRISE CLOUD SERVICES MASTER AGREEMENT (EXCERPT) CUSTOMER: APEX FINANCIAL ENTERPRISES LLC | VENDOR: CLOUDSCALE TECHNOLOGIES INC. EXECUTION DATE: JANUARY 14, 2025 ================================================================================ SECTION 9: CONFIDENTIALITY, SECURITY, AND DATA BREACH NOTIFICATION Section 9.2. Security Incident Notification SLA In the event Vendor discovers or reasonably suspects any unauthorized access, breach, exfiltration, or compromise of Customer Confidential Information or Customer Personal Data ("Security Incident"), Vendor shall notify Customer in writing within twenty-four (24) hours of initial discovery or suspicion. Vendor shall provide a preliminary root-cause summary and an active mitigation plan within forty-eight (48) hours. Section 9.5. Backup and Recovery Guarantee (RTO & RPO) Vendor guarantees a Recovery Point Objective (RPO) of not more than one (1) hour and a Recovery Time Objective (RTO) of not more than four (4) hours for all Customer Data. Vendor warrants that 100% of production data backups are validated and recoverable. SECTION 12: LIMITATION OF LIABILITY AND INDEMNIFICATION Section 12.1. Aggregate Liability Cap Except as provided in Section 12.4, each party’s maximum aggregate liability arising out of or related to this Agreement shall be limited to the total fees paid by Customer in the twelve (12) months preceding the incident ("Standard Cap"). Section 12.4. Uncapped Liabilities & Super-Cap The limitations in Section 12.1 shall NOT apply to: (a) Vendor's breach of Section 9 (Confidentiality and Security), (b) gross negligence or willful misconduct, or (c) Vendor's third-party IP indemnification obligations.