KEEPABLE SENDER AGREEMENT Version 2026-09-06 This Agreement is between Ciphersec Limited ("Keepable"), a company incorporated in the Federal Republic of Nigeria, and the organisation applying for a sender account ("you"). It governs everything you send through Keepable. Our Terms of Service (https://keepable.co/terms/) cover recipient mailboxes; the Data Processing Addendum (https://keepable.co/dpa/) forms part of this Agreement and governs personal data you send us. Keepable currently onboards organisations registered with the Corporate Affairs Commission as an incorporated company (RC), incorporated trustee (IT), or limited liability partnership (LLP). References to an organisation, applicant, or authorised representative in this Agreement apply to each of those legal forms as described below. The applicant confirms that they submitted the application and acknowledges this exact version of the Agreement. That confirmation does not, by itself, establish that the organisation accepted the Agreement. An independently identity-verified authorised representative whose active role is recorded by the Corporate Affairs Commission must separately ratify this exact version on the organisation's behalf. If the applicant and authorised representative are the same natural person, one verified confirmation may record both acts, but Keepable records the two capacities separately. We do not approve the account unless the required confirmations are attributable to the verified natural person or persons. 1. WHAT KEEPABLE DOES Keepable is a digital mailbox. You deliver bills, statements, agreements, consent requests and notices to a person's mailbox, addressed by their National Identification Number or their verified email. They read, sign, download and verify those documents from any device, and they keep them. We are the delivery and evidence layer. We are not the author of what you send, we do not decide what you send, and we do not decide who you send it to. 2. GETTING APPROVED You cannot send to real recipients until we have verified your organisation. The sandbox is open before that, and everything sent there is synthetic and free. What we check. We check your registered name, CAC number, legal form and active status against the Corporate Affairs Commission register, and the identity of the applicant through an accredited identity-verification provider. We also check that the named authorised representative has an active, matching registry role appropriate to the legal form: for an RC, a director, company secretary or authorised signatory; for an IT, a trustee or authorised signatory; and for an LLP, a partner, designated partner or authorised signatory. The applicant confirms. We ask the person identified as the applicant, in their own Keepable account, to confirm that their NIN was used for the application, that they made the application, and that they acknowledge this exact Agreement version. This attributes the submission to a verified natural person. It does not alone authorise the organisation's sender account. The authorised representative ratifies. We ask the named authorised representative, in their own Keepable account, to confirm that they hold the stated active role, agree to be recorded as responsible for the sender account, and ratify this exact Agreement version on the organisation's behalf. We will not approve an account without that confirmation. If the applicant names themselves as the authorised representative, we still require a verified confirmation that records both capacities. The applicant warrants that the application is true and that they are authorised to submit it. The authorised representative warrants that they hold the stated role, have authority to ratify this Agreement for the organisation, and that the organisation's application is true. What we keep, and why. We record the last four digits of each National Identification Number we are given, the verified name returned by the identity provider, references to the identity and registry checks, and the agreement version, immutable artifact address and cryptographic hash confirmed. We also retain the numbers themselves, encrypted, so that if a sender account is later used to impersonate an organisation there is a person we and the authorities can identify. This is disclosed to each person at the point we collect it. It is held for the life of the account and the period afterwards during which a claim arising from it could be brought, and there is no routine access to it: it is opened only for a specific investigation or to send a required agreement-ratification request to the previously verified person after the Agreement changes. 3. YOUR ACCOUNT, YOUR KEYS You are responsible for everything sent under your account. Keep your API keys secret; treat a leaked key as a compromised account and rotate it. Sandbox and live keys are distinct, and a sandbox key can never reach a real person. Members you invite act for you. Removing a member is your job, not ours. 4. WHAT YOU MAY SEND You may send documents to people who have a relationship with you and a lawful basis to receive them. You may not use Keepable for unsolicited marketing, for anything unlawful, for content designed to deceive a recipient about who sent it, or to impersonate another organisation. Do not collect identity or access information for Keepable. You may not ask a recipient to send you their NIN, face capture, passkey, password, BVN or OTP on Keepable's behalf, or tell them that Keepable requires them to provide any of those items to you. Keepable handles its own identity check; you must not turn a delivery notice into a credential or identity-data collection form. What we do to what you send. We sanitise the HTML you supply, strip metadata from files you upload, render your document to a sealed PDF, and hash and seal the result. We do not edit your words. Where you choose a template supplied by Keepable, the completed document is still issued by your organisation unless it clearly identifies Keepable as the sender. Where a document type requires a disclosure under Nigerian data-protection law (a purpose, a lawful basis, a retention note), we require it before the send goes out, because a document that cannot say why it exists is one the recipient cannot act on. We may hold a delivery where the recipient's mailbox does not meet the assurance the content requires. Binding correspondence needs an identity-verified recipient; we will not deliver it to a mailbox proven only by email. 5. DATA PROTECTION For the personal data you send through Keepable, you are the data controller and we are your processor under the Nigeria Data Protection Act 2023. You decide the purpose; we carry it out on your instruction. The Data Processing Addendum sets out the detail and takes precedence over this section where they differ. Two consequences worth stating plainly, because they surprise people: - Consent is yours to honour. Where you collect a person's consent through Keepable, the record is ours to keep and yours to act on. If they withdraw it, the mechanism is yours: we can show that they withdrew, and we cannot make you stop. - A recipient's mailbox is theirs, not yours. A document delivered to a person stays available to that person. Ending this Agreement does not withdraw what you have already sent. For the data we hold about you (your organisation records, your members, and the identity and registry checks above), we are the controller, and our Privacy Notice (https://keepable.co/privacy/) applies. 6. MONEY Delivery is prepaid. You add credit to your account and each live delivery draws against it; a send with insufficient credit does not go out. Sandbox sends draw nothing. Current prices are those published in your account at the time of the send. Credit is not refundable for change of mind and does not expire except where it was granted as a promotional credit, in which case its expiry is stated when it is granted. 7. SEALING AND VERIFICATION When a correspondence is complete, its final PDF evidence copy is hashed and sealed by Keepable. The seal binds that exact PDF to an immutable snapshot of the sending organisation at the time of issue, including its legal name, its logo where present, and its CAC registration number. Anyone holding the final PDF can check the seal and sender snapshot at our public verifier without an account or a separate receipt code. You authorise issue and delivery through your authenticated Keepable account or API credentials. Keepable applies the cryptographic seal as the delivery and evidence provider. Unless a document contains a separate signature made with a sender-controlled key, the Keepable seal does not claim that you applied your own digital signature. That is a statement about origin and integrity, not about the truth of what your document says. We seal what you issue. Whether it is correct is between you and your recipient. Where a recipient signs, the signature is bound to the credential they authenticated with. We record how they proved who they were, and that record travels with the document. 8. SUSPENSION We may suspend an account without notice where we believe it is being used to impersonate an organisation, where sending is unlawful, where a security compromise makes suspension the safer course, or where the authorised representative withdraws the confirmation or no longer holds the active registry role on which the account was approved. Suspension stops sending. It does not delete what you have already sent, and it does not remove documents from the mailboxes of people who received them. Where the reason is correctable, we will say what it is and what would fix it. 9. TERM AND ENDING IT This Agreement runs until either of us ends it. You may close your account at any time from the portal. We may end it on 30 days' written notice, or immediately in the circumstances in section 8. On termination: sending stops, unspent credit is forfeited unless the termination was ours and without cause, and we retain your organisation and identity records for the periods set out in section 2 and in the Data Processing Addendum. Documents already delivered remain with their recipients. 10. LIABILITY Neither of us excludes liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be excluded. Otherwise, neither of us is liable for indirect or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings. Our total liability arising out of this Agreement is limited to the fees you paid us in the twelve months before the event giving rise to the claim. You will indemnify us against claims brought by a recipient or a regulator arising from what you sent, from your lawful basis for sending it, or from a breach of section 4. 11. CHANGES We may revise this Agreement. Where a revision materially changes your obligations we will give you 30 days' notice and ask you to accept the new version; where it does not, we will publish it and note the version. Your account records the exact version, immutable artifact address and cryptographic hash accepted, by whom, in which capacity, and when. A new current version requires a new acceptance before sending or approval can continue. 12. GOVERNING LAW Nigerian law governs this Agreement. The courts of Lagos State have exclusive jurisdiction, save that either of us may seek injunctive relief in any competent court. 13. CONTACT Ciphersec Limited, senders@keepable.co. Data-protection questions: dpo@keepable.co.