Bank Data Access Terms.

(Schedule to Service Agreement — Sligo Data Solutions)

This Schedule forms part of, and is incorporated into, the Service Agreement between Sligo Data Solutions ("we", "us", "SDS") and the client named in that Agreement ("you", "the Client"). It applies specifically to the bank account data access and transaction retrieval service described below.

1. What this service does
With your explicit authorisation, we retrieve read-only transaction and account data from your bank account(s) using Enable Banking, a regulated third-party account information service provider. We use this data to provide automated bookkeeping and financial reporting insights as part of the wider services described in your Service Agreement.

2. Nature of access
Access is read-only. We can view account details, balances, and transaction history. We cannot move money, initiate payments, or make any changes to your bank account. Access is provided through Enable Banking, which operates under applicable open banking (PSD2) regulation as a licensed account information service provider. SDS is not itself a licensed financial institution and relies on Enable Banking's regulatory status to provide this access.

3. Your authorisation and consent
Before any data is retrieved, you will be asked to log in directly with your own bank and explicitly authorise access through your bank's own secure authentication process. We never see or store your online banking login details. Consent is time-limited (typically up to 90 days, depending on your bank) and must be renewed periodically for access to continue. We will notify you before consent is due to expire. You may revoke this consent at any time, either directly through Enable Banking's consent management portal, or by notifying us, after which we will stop retrieving new data from the relevant account.

4. Data we collect
Account holder name and account identifiers (e.g. IBAN); account balances; transaction history including dates, amounts, currency, descriptions, and counterparty details as provided by your bank.

5. How we use this data
Data retrieved through this service is used solely to provide the bookkeeping automation and financial reporting services described in your Service Agreement. We do not sell your data, use it for advertising, or share it with any party except as described below.

6. Sub-processors
We use Enable Banking (provides the regulated connection to your bank and retrieves data on our behalf) and Supabase (provides secure database hosting for storing retrieved data) to deliver this service.

7. Data storage and security
Data is stored in a private database, access-restricted so that only our automated systems and authorised personnel can reach it. Row-level security controls restrict programmatic access to service accounts only. Data in transit is encrypted (HTTPS/TLS) at every stage of retrieval and storage.

8. Data retention
We retain your transaction data for the duration of our engagement with you, and for a period afterward as required to meet our own legal and accounting obligations, or as otherwise agreed in your Service Agreement. You may request deletion of your data at any time, subject to any retention we are legally required to maintain.

9. No payment initiation
This service provides account information only. We do not, and cannot, initiate payments, transfers, or any transaction on your bank account through this service.

10. Liability
We are not responsible for outages, errors, or delays caused by your bank, Enable Banking, or other third parties outside our reasonable control.

11. Termination
Either party may end this specific data access arrangement independently of the wider Service Agreement, by written notice.

12. Governing law
This Schedule is governed by the laws of Ireland.