Confidentiality Agreement - solid.garden

Preamble

This Confidentiality Agreement is a legally binding commitment to protect your sensitive hydrocarbon industry data. In the oil and gas sector, seismic surveys, well logs, and geological interpretations represent millions in investment and significant competitive advantage. We treat your data with the confidentiality it deserves.

This agreement is entered into between DÉNES SZILÁRD e.v. ("Disclosing Party" and "Receiving Party") and the user or entity registering for solid.garden services ("Counterparty").

1. Definition of Confidential Information

"Confidential Information" means any non-public information, technical data, or know-how, including but not limited to:

1.1. Seismic & Geophysical Data: 2D/3D seismic data (SEG-Y, pre-stack and post-stack volumes), seismic attributes (AVO, inversion, spectral decomposition results), gravity and magnetic surveys, MT and CSEM surveys, velocity models (VTP, RMS, interval velocities).

1.2. Well & Borehole Data: Well logs (gamma ray, resistivity, sonic, density, neutron porosity), image logs (FMI, borehole imaging), core data (core descriptions, plug measurements, analysis results), well tops (formation tops, marker picks, correlation data), production data (rates, pressures, decline curves, test results).

1.3. Geological & Interpretation Data: Geological maps (structure maps, isopachs, facies maps), cross-sections (structural and stratigraphic sections), reservoir characterization (property distribution, NetPay, HC volumes), prospect evaluations (lead inventories, risk assessments, resource estimates), technical reports (volumetrics, reserve reports, expert interpretations).

1.4. Business & Strategic Information: License round data (block evaluations, bidding strategies), farm-in/farm-out materials (data rooms, presentation materials), partnership discussions (joint venture negotiations, term sheets), project budgets (AFE estimates, cost breakdowns, economics), communications (emails, messages, project discussions).

1.5. Any information marked as "confidential" or that a reasonable person would understand to be confidential given the nature of the information and the circumstances of disclosure.

2. Obligations of Receiving Party

2.1. Confidentiality. The Receiving Party agrees to maintain the confidentiality of all Confidential Information and not to disclose it to any third party without the prior written consent of the Disclosing Party, except as required by law or to subprocessors who have agreed to confidentiality terms no less protective than those in this Agreement.

2.2. Use Limitation. The Receiving Party agrees to use Confidential Information only for the purpose of receiving or providing services under this Agreement.

2.3. Need-to-Know Access. The Receiving Party shall restrict disclosure of Confidential Information to its employees, contractors, or agents who have a need to know such information for the purpose of this Agreement and who have signed confidentiality agreements with obligations no less restrictive than those contained herein.

2.4. Standard of Care. The Receiving Party shall protect Confidential Information with the same degree of care used to protect its own confidential information of a similar nature, but in no event less than reasonable care.

2.5. No Copying. The Receiving Party shall not copy, reproduce, or distribute Confidential Information except as necessary for the services contemplated under this Agreement.

3. Data Security Measures

3.1. Encryption. The Receiving Party agrees to implement and maintain AES-256 encryption for data at rest and TLS 1.3 encryption for data in transit.

3.2. Access Controls. Access to Confidential Information is restricted through JWT-based authentication, role-based access permissions, and session timeout controls.

3.3. Audit Logging. Comprehensive audit logs track all data access by user and company, including timestamps, actions performed, data accessed or modified, IP address and geolocation, and outcome.

3.4. Multi-Tenant Architecture. The platform uses company_id-based isolation at the database level. All database queries include company_id filtering without exception, users can only access data belonging to their company, and no cross-company data access is technically possible.

3.5. Infrastructure Security. Hosting is provided on Railway Corporation infrastructure (SOC 2 Type II compliant, EU-U.S. Data Privacy Framework certified) with regular security updates and vulnerability management.

4. No AI Training

4.1. The Receiving Party shall not use any Confidential Information to train, develop, or improve machine learning models, artificial intelligence systems, or automated decision-making technologies without the separate, explicit written consent of the Disclosing Party.

4.2. This commitment is legally enforceable under this Agreement and includes: (a) no use of your seismic data for AI training; (b) no use of your well logs for pattern recognition analysis; (c) no learning from your geological interpretations; (d) no use of your project files for third-party model training.

4.3. Any future AI features would require explicit opt-in consent from the Disclosing Party.

5. Third-Party Data Sharing

5.1. The Receiving Party only engages subprocessors who meet strict security standards and who are bound by GDPR-compliant data processing agreements.

5.2. Authorized Subprocessors: (a) Railway Corporation for hosting infrastructure (EU-U.S. Data Privacy Framework certified, SOC 2 Type II compliant); (b) Stripe, Inc. for payment processing (PCI DSS Level 1 certified, EU-U.S. Data Privacy Framework certified).

5.3. Prohibitions: The Receiving Party does not sell, rent, or trade your data to third parties. There is no advertising, analytics, or marketing data sharing. No data is shared with other E&P companies or industry partners.

5.4. Exceptions: Data may only be disclosed when required by law, court order, subpoena, or to protect the Receiving Party's rights, property, or safety. Where legally permitted, the Disclosing Party will be notified before such disclosure.

6. Data Retention & Deletion

6.1. Active Projects: Data is retained while projects are active.

6.2. Completed Projects: Subsurface data is deleted after 30 days. Personal data is retained for 8 years per Hungarian tax law requirements. Automated backups are retained for 7 days.

6.3. Your Rights: You may request export of your data at any time in common formats. You may request deletion of subsurface data upon project completion. You may request deletion of personal data subject to legal retention requirements. Automated deletion process applies to completed projects. Confirmation of data deletion is provided upon request.

6.4. Secure Deletion: Upon termination or at the Disclosing Party's request, the Receiving Party shall return or securely delete all Confidential Information and provide written certification of deletion within 30 days.

7. Data Subject Rights

7.1. GDPR Rights (EU/UK/EEA): Right to access personal data; right to rectification of inaccurate data; right to erasure ("right to be forgotten"); right to restrict processing; right to data portability; right to object to processing; right to withdraw consent; right to lodge a complaint with supervisory authority (NAIH in Hungary).

7.2. CCPA/CPRA Rights (California): Right to know what data is collected; right to delete personal information; right to correct inaccurate data; right to opt-out of data sharing; right to limit use of sensitive data; right to non-discrimination.

8. Breach Notification

8.1. In the unlikely event of a data breach, the Receiving Party will notify the Disclosing Party without undue delay and within 72 hours of becoming aware of the breach.

8.2. Notification will include detailed information about the breach nature, categories of data affected, likely consequences, and remediation steps taken.

8.3. The Receiving Party will cooperate with supervisory authorities as required and provide information necessary for the Disclosing Party to fulfill its own breach notification obligations.

9. Exclusions from Confidential Information

Confidential Information does not include information that: (a) is or becomes public knowledge through no fault of the Receiving Party; (b) was rightfully in the Receiving Party's possession prior to disclosure; (c) is independently developed by the Receiving Party without use of Confidential Information; (d) is rightfully obtained from a third party without confidentiality restrictions; or (e) is required to be disclosed by law or court order, provided the Receiving Party gives the Disclosing Party prior notice where legally permitted.

10. Term and Survival

10.1. This Agreement commences on the Effective Date and continues during the term of service provision.

10.2. The obligations of confidentiality shall survive the termination or expiration of this Agreement for a period of 5 years, or indefinitely for trade secrets as defined by applicable law.

10.3. Upon termination, the following provisions survive: confidentiality obligations (indefinitely for trade secrets); data security and deletion requirements; audit and record-keeping obligations; liability and indemnification provisions.

11. Remedies

The parties agree that monetary damages may not be a sufficient remedy for unauthorized disclosure of Confidential Information. The Disclosing Party shall be entitled to seek equitable relief, including injunction and specific performance, as a remedy for any breach or threatened breach of this Agreement, without the necessity of posting a bond or proving actual damages.

12. Governing Law and Dispute Resolution

12.1. This Agreement is governed by the laws of Hungary.

12.2. Any disputes arising under this Agreement shall be resolved in the courts of Hungary.

12.3. For EU consumers, this does not deprive you of the protection of mandatory provisions of the law of your country of residence.

12.4. For matters relating to GDPR compliance, either party may refer a dispute to the supervisory authority with primary jurisdiction: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1125 Budapest, Szilágyi Dezső square 3., Phone: +36 1 391-1400, Email: ugyfelszolgalat@naih.hu, Website: www.naih.hu.

13. Contact Information

For questions about this Confidentiality Agreement or data handling practices, please contact:

DÉNES SZILÁRD e.v.
Magyarország 8171 BALATONVILÁGOS, PONTY UTCA 4
Hungarian tax number: 59835165-1-34
Email: szilard@solid.garden

BY ACCEPTING THIS CONFIDENTIALITY AGREEMENT, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY ITS TERMS.