# Cookie policy Source: https://legal.autheo.com/legal-agreements/cookie-policy This cookie policy explains how Autheo LLC (“Autheo”, “we”, “us”) uses cookies and similar tracking technologies for our website and services for Autheo (“Services”). By accessing or using our Services, you agree to the use of cookies as described in this policy. ### **What are cookies?** Cookies are small text files that websites place on your device to: * Store login information * Remember your preferences and activities * Analyze user behavior and usage patterns ### **Types of cookies we use** #### i. Essential cookies Required for the basic functionality of our Services, including login authentication, session management, and security. These cookies cannot be disabled. #### ii. Performance and analytics cookies Helps us understand user interactions, monitor performance, and improve our services by tracking page views, clicks, and feature usage. #### iii. Functional cookies Improves functionality by remembering your preferences, settings, and customizations like language settings or UI preferences. #### iv. Advertising and third-party cookies Used by third-party partners to understand the browsing habits across our Services to deliver relevant advertisements. These cookies also track advertising performance. ### **How we use cookies** In Autheo, cookies are used to: * Provide, maintain, and optimize our Services in a secure manner * Monitor usage and performance of Services * Improve user experience by remembering user preferences and activities * Offer personalized content, advertisements, and communications by analyzing user behavior ### **Managing your cookies** Apart from the essential cookies, you can manage or disable cookies via the browser settings. Note that some Autheo features may be affected if cookies are disabled. Here’s how you can manage cookies from your browser: * Chrome: Settings > Privacy and Security > Cookies and other site data * Firefox: Preferences > Privacy and Security > Cookies and site data * Safari: Preferences > Privacy > Manage website data You may also opt out of targeted advertising (third-party) cookies via programs like Your Online Choices (Europe) or Network Advertising Initiative (US/Global). ### **Third-party cookies** Some of Autheo’s third-party partners may place cookies (e.g. analytics and marketing platforms), which Autheo does not control. Please review their respective cookie policies for more information. ### **Changes to the cookie policy** This cookie policy may be updated periodically. The updates will be posted on this page, with the latest date at the top of the page. Continued use of our Services indicates acceptance of the updated cookie policy. ### **Contact us** For questions regarding this cookie policy or our use of cookies, please contact [legal@autheo.com](mailto:legal@autheo.com). \ \\ # End user license agreement Source: https://legal.autheo.com/legal-agreements/end-user-license **END USER LICENSE AGREEMENT** **FOR** \*\*Autheo LLC \*\* **04/29/2025** ** ** This Terms of Use Agreement (the “Agreement”) is between you (“you” or the “User”) and the service operator, Autheo LLC (“Company”). By using any services made available through the Autheo websites ([www.autheo.com](http://www.autheo.com), [www.launchlegends.io](http://www.launchlegends.io), etc.) (the “Website”), Autheo Mobile Applications (individually, an “Application”) or Community Features as defined herein (collectively, “Services”), or Autheo affiliates, you agree that you have read, understood, accepted and agreed to all of the terms and conditions contained in this Agreement, as well as our Privacy Policy and Consent Form, which have incorporated GDPR regulations. **This Agreement is a legally binding contract.**  Please carefully read through this Agreement and related notices before using any of the Services. Should you not agree to the terms of this Agreement, please disable your account and immediately stop your use of the Autheo Website and any and all of its Services. For more information on the Company or our Services, you may refer to the company and license information found on the Website. If you have questions regarding this Agreement, please contact the Company via our Customer Support team at [legal@autheo.com](mailto:legal@autheo.com) ### **Modifications of Terms and Conditions** The Company reserves the right to modify or change the terms and conditions of this Agreement at any time in its sole discretion. the Company will provide notice of these modifications or changes by updating the revised Terms of Use on its Website and changing the revision date on this page. Any and all modifications or changes to this Agreement will be effective immediately upon their announcement on the Website or their release to Users. Your continued use of the Company’s Services constitutes acceptance of this Agreement as modified. **If you do not agree to be bound by these modifications, please discontinue use of the Company Website immediately.** ### **Eligibility** By registering to use the Company’s Services, you have affirmed that you are an individual at least thirteen (13) years of age, or a firm, corporation or other entity in good standing, with full legal capacity to enter into this Agreement. If such affirmation shall prove false, the Company retains the right to cancel or freeze your account and, if applicable, to seek damages and/or injunctive relief against you, your guardian and/or any other party deemed legally responsible for such false affirmation. Accounts for all User may be established on the Autheo Website in accordance with its terms and conditions. If the Company discovers accounts associated with any User being utilized in violation of its terms and conditions, the Company reserves the right to freeze, suspend, or terminate all of that User’s accounts. The User is responsible at all times for the maintenance of his or her login and password credentials. Any unauthorized usage of your Autheo account should be reported to the Company immediately. The Company is not responsible for any loss or damages resulting from the User’s failure to report unauthorized use of his or her account. Further, upon registration for the Website the User shall provide the Company with complete and accurate personal information, if required, and must promptly update any and all information when it changes. ### **Prohibition of Use** By accessing and using the Services, you acknowledge and declare (a) that you are not on any trade or economic sanctions lists of any applicable jurisdiction, including but not limited to the United Nations Security Council Sanctions List, and (b) that you are not a citizen or resident of any country that disallows participation in digital asset ecosystems. The Company retains the right to select markets and jurisdictions in which to operate and may restrict or deny its services to Users in certain countries for any reason whatsoever. Prohibited persons shall not use or access the Autheo Website or any of its Services. ### **Governing Law** This Agreement and the Autheo Website are governed by the laws and regulations of the United States of America, state of Wyoming. By using the Services, the User subjects himself or herself to such laws and regulations. This provision shall apply regardless of the residence, domicile or citizenship of the User. ### **Autheo Account Registration & Requirements** #### **Registration** All Users may have to register for an Autheo Account before using certain site features. To register for an account, you may be required to provide your real name, email address and password, and accept the Terms of Use, Privacy Policy and Consent Form.  By registering for an Autheo Account, you declare that all information provided to the Company is true, accurate and complete to the best of your knowledge. The Company may, in its sole discretion, refuse to open an account for any User at any time. #### **User Identity Verification** By registering an account with the Company, the User agrees to share his or her personal information for the purpose of identity verification, if necessary. This information is used specifically for the detection of possible money laundering, terrorist financing, fraud and other financial crimes. In addition to providing this information, to facilitate compliance with global industry standards for data retention, the User agrees to permit the Company to keep a record of such information for the lifetime of the account plus 5 years after account closing. The User also authorizes the Company to make inquiries, either directly or through third parties, that are deemed necessary to verify the User’s identity or to protect the User and/or the Company from financial crimes such as fraud. The Identity Verification information the Company requests may include, but is not limited to, the User’s Name, Email Address, Contact Information, Telephone Number, Username, and Government Issued ID. In providing this required information, the User affirms that all information and documentation is accurate and authentic. Post-registration, the User guarantees that all information provided remains truthful and complete, and that it will be updated in a timely manner with any changes. If there is reason to believe information provided by the User is wrong, untruthful, outdated or incomplete, the Company reserves the right to request corrections, remove relevant information directly and terminate all or part of the Company’s Services to the User. The User shall be solely responsible for any loss or expenses incurred during the use of the Company Service if they cannot be reached using the contact information provided. The User hereby acknowledges and agrees that he or she has the obligation to update all information provided to the Company in accordance with this Agreement. #### **Account Usage Requirements** Autheo accounts may be used only by the person in whose name they are registered. The Company reserves the right to suspend, freeze or cancel accounts that are used by persons other than the registered User. The Company assumes no legal responsibility for such unauthorized account usage. #### **Account Security** The Company prioritizes maintaining the safety of funds utilized within the Autheo ecosystem and has implemented industry standard protections for its services. However, account-level risks may also be created by individual User actions. We strongly urge that you take independent precautions to protect access to your account and the security of your personal information. You are solely responsible for the safekeeping of your Autheo account and password, and you shall be responsible for all activities conducted under your login name and password (including but not limited to information disclosure, information posting, consent to various rules and submission of Agreements by clicking on the Website, online renewal of Agreement, etc.). **You hereby agree that**: (a) you will notify the Company immediately if you become aware of any unauthorized use of your Autheo account and password by any person or any other violation of security rules and regulations; (b) you will observe the security, authentication, dealing, charging, withdrawal mechanism and other procedures of the Website/service; and (c) you will log out from the Website by taking proper steps at the end of every visit. The Company will not be responsible for any financial loss or breach of security caused by your failure to comply with the above Account Security provisions. #### **Dispute Resolution** The Company reserves the right to resolve issues and disputes in its sole discretion. Such issues may include infringement of others’ rights, violation of applicable laws and regulations, abnormal trades, and other issues not explicitly mentioned in the Terms of this Agreement. Users agree to bear the costs arising from the process of dispute resolution. #### **Guidelines for Usage of Services on the Website** You hereby agree to the following covenants. All activities that you engage in while using the Company’s Services:     ● will be in compliance with the requirements of applicable laws and regulations, the various published guidelines of the Company, and the terms and conditions of this Agreement;      ● will not violate the public interest, public ethics or others’ legitimate interests; and     ● will not constitute or promote evasion of taxes or fees payable. You covenant and agree that you will not use any data or information displayed on the Autheo Website for commercial purposes without the prior written consent of the Company. You will use the site in accordance with its Terms of Use and Privacy Policy. You shall not attempt to interfere with the normal operations of the Company. Examples of such interference may include, but are not limited to     ● using a device, software or subroutine to interfere with the website,     ● overloading network equipment with unreasonable data loading requests, or     ● executing malicious or fraudulent token or project launches By accessing the Services, you agree that the Company has the right to unilaterally determine whether you have violated any of the above covenants, and to take actions to apply relevant rules and sanctions without your consent or without prior notice to you. Examples of such actions may include, but are not limited to:     ● freezing your account,     ● reporting the incident to authorities,     ● publishing the alleged violations and actions that have been taken in response thereto, and     ● deleting any information you have published that is deemed to be in violation of the above covenants. In case of any legal proceeding against you by a third party by reason of an alleged violation of these covenants or any other provision of this Agreement, you shall independently undertake the defense of such legal proceeding and shall indemnify and hold harmless the Company from any and all actions, claims, or costs arising therefrom, including damages of any type, fines, losses caused by administrative sanctions of any kind, and reasonable attorney’s fees incurred by the Company in the defense thereof. #### **Description of Services** The Company provides an online digital asset ecosystem for a suite of proprietary services including, but not limited to, nodes, tokens and a developer web3 and AI service portfolio that helps users discover and directly interact with each other and projects a variety of blockchains. Once you purchase node(s) or token(s), the Company does not retain custody or control, and it does not execute or effectuate purchases, transfers, or sales of tokens, nor will it refund any token loss due to user error. The Company shall host an ecosystem for creators and/or purchase of tokens within its ecosystem. The Company does not make any representation or warranty that the tokens hosted on its Website may be sold or converted to any other form by the User, in any exchange or elsewhere, once purchased. The Company reserves the right, in its sole discretion, to cancel or suspend any token launch or hosting of trading pair, as well as any developer portion of the ecosystem, should viruses, bugs, hacking or other unauthorized human intervention or other causes corrupt their administration, security, fairness, integrity or proper operation. Notification of such cancellation or suspension will be provided by the Company promptly to its users. The Company operates a digital asset ecosystem and is not a market maker. The information published on the Autheo Website is for informational purposes use only. **The Company does not provide authoritative market data, investments or investment advice, and disclaims any liability for the use or interpretation of information published on its Website or in other communications media. The Company encourages all Users to exercise prudence, and to participate responsibly and within their own financial means.** Users must register and open an account with the Company and deposit digital assets prior to commencement of trading. Users may request the withdrawal of their assets, subject to the conditions and limitations set forth in this Agreement. #### **Conditions of Participation** By interacting with the Autheo Website, Users agree to be bound by the rules and the decisions of the Company, which shall be final and binding in all respects. The Company, in its sole discretion, may suspend an account if the User engages in conduct or otherwise utilizes any information the Company deems improper, unfair or otherwise adverse to the operation of the Website, or in any way detrimental to other participants, including: * Any person sanctioned civilly or criminally by any securities or other law enforcement agency in any jurisdiction, for price manipulation, securities fraud, hacking or any other securities or technology violation involving moral turpitude; and * Any person prohibited from participating pursuant to court order. In addition, conduct that would be deemed improper also includes, but is not limited to: * Falsifying personal information required to interact with the Website; * Engaging in any type of financial fraud including unauthorized use of a User account or manipulation of a token or project; * Colluding with any other individual(s) or engaging in any type of market manipulation; * Any violation of the Terms of Use; * Using any form of automated means to obtain, collect or access any information on the Website or of any User for any purpose; * Tampering with the computer programs or any security measure associated with a Website; and * Abusing the Website in any way. Users further acknowledge that their removal and/or ban from the Website shall in no way prevent the Company from pursuing criminal or civil proceedings in connection with such conduct. #### **Service Fees** The Company reserves the right to levy service fees on Users who use its Services, which fees may be adjusted by the Company at any time in its sole discretion. #### **Disclaimer of Warranties** The Company strives to maintain the accuracy of information posted on its Website; however, it cannot guarantee the accuracy, suitability, reliability, completeness, performance or fitness for purpose of its Website content, and will not accept liability for any loss or damage that may arise directly or indirectly from such content. Information on the Autheo Website is subject to change without notice and is provided for the primary purpose of facilitating independent decisions by its Users. While the Company emphasizes platform security to ensure the continuity and security of its Services (announcements will be made in event of downtime/maintenance), it shall not be held liable for User losses in the event of unforeseen circumstances, including but not limited to Acts of God, malicious targeted hacking, service outages and terrorist attacks. The Company reserves the right to cancel, roll back or block transactions of all types on its platform in case of such an abnormal event. #### **Provision of Services** The Company will provide the Services on an “as is” basis and in “commercially available” condition. It does not offer any form of warranty with regard to the Services’ reliability, stability, accuracy or completeness of the technology involved. The Company cannot control the quality, security or legality of the wager involved in any transaction, truthfulness of the transaction information, or capacity of the parties to any transaction to perform their obligations. Prior to your use of the Company’s Services you should carefully consider the investment risks, available information, legality and validity of such transaction. #### **Limitation of liability** You acknowledge and agree, the Company will in no case be liable for any of your losses caused by any of the following events, including but not limited to:     ● Losses of profits, goodwill, usage or data, or any other intangible losses;     ● Use of or failure to use the Company’s Services;     ● Unauthorized use of your account or unauthorized alteration of your data by third parties;     ● Your misunderstanding of the Company’s Service; or     ● Any other losses related to the Company’s Service which are not directly attributable to the gross negligence or willful misconduct of the Company, its agents or employees. In no event shall the Company be liable for any failure or delay of service resulting from regular network maintenance or external factors such as power failure, natural disaster, service provider problems or governmental acts. The Company is not to be held responsible for: any incorrect, invalid or inaccurate information; human errors; postal delays/postage due mail; technical malfunctions; failures, including public utility or telephone outages; omissions, interruptions, deletions or defects of any telephone system or network, computer online systems, data, computer equipment, servers, providers, or software (including, but not limited to software and operating systems that do not permit an entrant to participate in a Contest), including without limitation any injury or damage to any entrant's or any other person's computer or video equipment relating to or resulting from utilizing the Website; inability to access the Website, or any web pages that are part of or related to the Website; theft, tampering, destruction, or unauthorized access to, or alteration of the Website or any user account, and/or images of any kind; data that is processed late or incorrectly or is incomplete or lost due to telephone, computer or electronic malfunction or traffic congestion on telephone lines or transmission systems, or the Internet, or any service provider's facilities, or any phone site or Website or for any other reason whatsoever; postal issues, typographical, printing or other errors, or any combination thereof. Any attempt by a customer, User, or any other individual or entity to deliberately alter, damage, or affect the Website or undermine the legitimacy of the Company’s operation of any part of its ecosystem is in direct violation of criminal and/or civil laws.  Should any attempt be made, the Company reserves the right to seek damages and other legal remedies from any such person or entity to the fullest extent permitted by law. #### **Indemnification** You agree to indemnify and hold harmless the Company, its affiliates, contractors, licensors, and their respective directors, officers, employees and agents from and against any claims and damages (including attorneys’ fees, fines or penalties imposed by any regulatory authority) arising out of your breach or our enforcement of this Agreement. This shall also apply to User violation of any applicable law, regulation, or rights of any third party during use of the Company Service. By registering and/or using the Website, you agree to indemnify, release and to hold harmless the Company, its parents, subsidiaries, affiliates and agents, as well as the officers, directors, employees, shareholders and representatives of any of the foregoing entities (collectively, the "Released Parties"), from any and all liability, claims or actions of any kind, including but not limited to injuries, damages, or losses to persons and property which may be sustained in connection with Autheo and/or the Website, as well as any claims based on publicity rights, defamation, or invasion of privacy. The Company may, in its sole and absolute discretion, require a User to execute a separate release of claims similar to the one listed above in this Paragraph as a condition of receiving any payout. #### **Announcements** Please be aware that all official announcements, news and promotions will be listed on the Website at [www.autheo.com](http://www.autheo.com). The Company shall not be held liable should Users incur losses arising from ignorance or negligence in relation to and all posted Announcements. #### **Termination of Agreement** All Users agree that the Company reserves the right to immediately suspend your account (and any accounts beneficially owned by related entities or affiliates), freeze or lock the funds in all such accounts, and suspend your access to the Autheo Website, if we suspect any such accounts to be in violation of the Terms of Service, Privacy Policy, KYC/AML acts or any applicable laws & regulations. The Company shall have the right to keep and use the transaction data or other information related to such accounts. The above account controls may also be applied in the following cases:     ● The account is subject to a governmental proceeding, criminal investigation or other pending litigation,     ● We detect unusual activity in the account,     ● We detect unauthorized access to the account, or     ● We are required to do so by a court order or by order of a regulatory/government authority. In case of any of the following events, the Company shall have the right to terminate this Agreement by cancelling your account, and may permanently freeze (cancel) the authorizations of your account on the Autheo Website and withdraw the corresponding Autheo account thereof:     ● termination by the Company of its Services to you,     ● registration by you as a Autheo Website User, directly or indirectly, in any other person’s name,     ● provision by you to the Company of any User information that is untruthful, inaccurate, outdated or incomplete;     ● in case this Agreement (including the rules) is amended, you expressly state and notify the Company of your unwillingness to accept such amendment; or     ● any other circumstance causing the Company to decide that it should terminate the Services. Should your account be terminated, the account and transactional information required for meeting data retention standards will be securely stored for a period of five (5) years. In addition, if a Contest is pending during the account termination process, the Company shall have the right to notify your counterparty of the situation. #### **Remaining Funds after Account Termination (normal)** Once the account is closed/withdrawn, the User will have 10 working days to withdraw all remaining digital assets from the account. #### **Remaining Funds after Account Termination (fraud/AML/violation of terms)** In case of an account termination by reason of allegations of fraud, money laundering, violation of law, violation of governmental regulation, or violation of the terms of this Agreement or other Autheo rule or regulation, the Company shall maintain full custody of the funds in such account until such allegations are resolved to the reasonable satisfaction of the Company and its counsel. Information concerning such account, including personal information pertaining to its owner, may be turned over to governmental authorities in the event such information is subject to a subpoena or comparable legal order. In case any dispute about a terminated account is not resolved within a reasonable time, the Company may seek an order to pay the proceeds of such account into a court of law or supervised wallet pending such resolution, and upon such payment shall have no further liability concerning such proceeds. #### **Compliance with Local Laws** It is the responsibility of the User to comply with the laws of his or her jurisdiction concerning the Services, and particularly as to cryptocurrency transactions. Users are also advised to consider the laws of their jurisdictions concerning taxation, withholding, collection, reporting and remittance to the appropriate tax authorities. All Users of the Services acknowledge and declare that their funds come from a legitimate source and are not derived from illegal activities. The Company will cooperate with law enforcement authorities globally and will not hesitate to terminate the account and/or seize or freeze funds of Users who are flagged or investigated by legal authorities. #### **Privacy Policy** The Company may announce and amend its privacy policy on the Autheo Website from time to time. The privacy policy shall be deemed an integral part of this User Agreement. The latest version of the Privacy Policy may be found on this page: [http://legal.autheo.com](http://legal.autheo.com) #### **Intellectual Property Rights** The content on the Website including, but not limited to, the text, software, scripts, graphics, photos, sounds, music, videos, interactive features and the like and the trademarks, service marks and logos contained therein (the "Intellectual Property"), are owned by or licensed to the Company, subject to copyright and other intellectual property rights under United States and foreign laws and international conventions. Content on the Website is provided to you AS IS for your information and personal use only and may not be used, copied, reproduced, distributed, transmitted, broadcast, displayed, sold, licensed, or otherwise exploited for any other purposes whatsoever without the prior written consent of the Company. The Company reserves all rights not expressly granted in and to the Website and the Intellectual Property. You agree to not engage in the use, copying, or distribution of any of the Intellectual Property other than expressly permitted herein. The User agrees not to circumvent, disable or otherwise interfere with security related features of the Website or features that prevent or restrict use or copying of any Intellectual Property or enforce limitations on use of the Website or the Intellectual Property therein. The Company may provide Services that allow the User to submit or transmit audio, video, text, or other materials (collectively, "User Submissions") to or through the Services. When you provide User Submissions, you grant to the Company, its parents, subsidiaries, affiliates, and partners a non-exclusive, worldwide, royalty-free, fully sublicensable license to use, distribute, edit, display, archive, publish, sublicense, perform, reproduce, make available, transmit, broadcast, sell, translate, and create derivative works of those User Submissions, and your name, voice, likeness and other identifying information where part of a User Submission, in any form, media, software, or technology of any kind now known or developed in the future, including, without limitation, for developing, manufacturing, and marketing products. You hereby waive any moral rights you may have in your User Submissions.\ \ In addition, you agree that any User Submissions you submit shall not contain any material that is, in the sole and absolute discretion of the Company, inappropriate, obscene, vulgar, unlawful, or otherwise objectionable (hereinafter, "Prohibited Content"). Posting of any Prohibited Content, in addition to any and all other rights and remedies available to the Company, may result in immediate account suspension or termination.\ \ We respect the User’s ownership of User Submissions. If the User owned a User Submission before providing it to us, the User will continue owning it after providing it to the Company, subject to any rights granted in the Terms of Use and any access granted to others. If a User Submission is deleted, by either the User or the Company, from the Services, the Company’s general license to that User Submission will end after a reasonable period of time required for the deletion to take full effect. However, the User Submission may still exist in backup copies, which are not publicly available. If the User Submission is shared with third parties, those third parties may have retained copies of the User Submissions. In addition, if the Company has made use of your User Submission before it was deleted, the Company retains the right to continue to make, duplicate, redistribute, and sublicense those pre-existing uses, even after the deletion of the User Submission. Terminating the User’s account on a Service will not automatically delete the User Submissions previously provided.\ \ The Company retains the right to refuse or remove a User Submission without notice to the User. However, the Company has no obligation to monitor User Submissions, and the User agrees that neither the Company nor its parents, subsidiaries, affiliates, employees, or agents will be liable for User Submissions or any loss or damage resulting from User Submissions.\ \ The User herein represents and warrants that you have all rights necessary to grant to the Company the license above and that none of your User Submissions are defamatory, violate any rights of third parties (including intellectual property rights or rights of publicity or privacy), or violate applicable law. #### **Complaints and Questions** If you have any complaints, feedback or questions, kindly contact [legal@autheo.com](mailto:legal@autheo.com) and the Company will use its best efforts to try to resolve them for you. # GDPR policy Source: https://legal.autheo.com/legal-agreements/gdpr-policy 04/29/2025 This GDPR policy discloses the privacy practices for Autheo LLC. (“the Company”) and any affiliates of the Company (“Affiliates”), whether now or hereafter formed. This GDPR Policy applies to information collected on this site ([https://www.autheo.com/](https://www.autheo.com/)) and other sites operated by the Company or its Affiliates (collectively “the Sites”).  **Compliance with GDPR. Effective as of May 25, 2018 (the “Effective Date”), the European Union and European Economic Area (EU/EEA) have adopted the General Data Protection Regulation (“GDPR”) covering all residents of the EU/EEA, whether or not the company issuing the privacy regulations is domiciled in the EU/EEA. The Company and its Affiliates have issued these amended privacy provisions in compliance with GDPR in order to provide appropriate disclosures and protection to all users of the Sites, whether or not domiciled in the EU/EEA. All existing users of the Sites as of the Effective Date will be notified promptly by email as to the existence of these provisions with a link to review the same.**   ### 1. Introduction Your privacy is important to us and we strive for a high level of protection in all processing of personal data.  As defined in GDPR and in accordance with applicable data protection legislation, the Company, or such Affiliate as may be specified at the end of this GDPR Policy, is the “data controller” and as such is responsible for the processing of your personal data as set out below. If you have any questions about this information, or if you wish to exercise any of your rights as set out below, contact the Company via the contact information listed under Section 6 below. ### 2. Processing of Personal Data #### a. General  The term ‘personal data’ refers to information which, directly or indirectly, may refer to you as an individual. Examples of personal data are name, email address, government-issued identification number, billing information, financial information (such as Know Your Customer and Anti Money Laundering disclosures), contact details, and IP address. Personal data processing refers to any action that we or a third party that we have engaged take with the personal data, such as its collection, registration, and storage. It also may include Cookies (see our Cookie Notice). Personal data may only be processed for specified and explicitly stated purposes and may not be subsequently processed for any purpose that goes beyond these stated purposes.  #### b. Website and Social Media We may collect personal data such as name, e-mail address, and other information which you voluntarily provide, e.g. when you choose to interact with the Company by subscribing to offerings, signing up for updates such as newsletters, deals, and offers, webinars, trade shows, events, etc. through email (which you can opt-out from via a link in each message sent through email), or by otherwise interacting with the Company or an Affiliate through one of the Sites. We also automatically receive and store information from your web browsers, such as IP address, language preferences, cookie information, and the pages you visit, to log files on our server. We use the information collected to respond to your requests regarding products and services, to improve the content on our Sites and the services, to track and prevent abuse of our Sites and services, and to develop anonymous usage statistics. We also use personal data for legally required notices, direct marketing, and advertising in accordance with applicable law and market practice. You may opt-out of such direct marketing and advertising at any time. We may use the information we collect with regard to how you, as a user, use the Sites so that we can analyze search and usage behavior to provide you with personalized content. Personal data may also be processed indirectly in connection with the development and administration of the Company’s IT systems. The legal grounds for such usage include (i) performance of a contract where you request services/resources through the Sites and (ii) legitimate interest for other processing activities, such as for the purpose of improving services and the content of the Sites, as well as for prevention of abuse and for statistical purposes. We delete collected personal data when the purpose of the processing has been completed. Our Cookie Notice includes retention periods in respect of cookies that we use. #### c. Customers buying our products online or potential customers When you are a customer buying products online, or a potential customer inquiring about our products and services, we may process the information you have volunteered, such as name, home and/or delivery address, telephone number, e-mail address, payment information, historical order information and the product you have bought. When you buy or inquire about, our products online via our Sites, we also collect the information specified in Section 2d. The legal grounds for such usage include (i) performance of a contract where you request services/resources through the Sites and (ii) legitimate interest for other processing activities, such as for the purpose of improving services and the content of the Sites, as well as for prevention of abuse and for statistical purposes. We delete most collected personal data when the purpose of the processing has been completed. However, some of this information is retained for the duration required by applicable securities laws and regulations, as well as tax and bookkeeping legal records requirements. #### d. Registered purchasers and users of our services and products We collect personal data such as name, address, phone number, e-mail address, payment information, designation, and other information that you voluntarily provide. When you use our services via our Sites, we also collect the information specified in Section 2d. We use the information collected to provide you with the services/products, to respond to your requests and handle support cases regarding products and services, to improve the support/services, and to develop anonymous usage statistics. The legal grounds for such usage include (i) performance of a contract where you request services/resources through the websites and (ii) legitimate interest for other processing activities, such as for the purpose of improving services and the content of the websites, as well as for prevention of abuse and for statistical purposes. We delete collected personal data when the purpose of the processing has been completed. However, some of this information is retained for the duration required by applicable securities laws and regulations, as well as tax and bookkeeping legal records requirements. #### e. Security for the protection of personal data We protect your personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by implementing appropriate technical and organizational security measures. #### f. Restrictions on the Disclosure of Personal Data We do not share personal data with third parties except under circumstances described herein. We may appoint external agents to perform tasks on our behalf, such as providing IT services or helping with marketing and recruitment, administration of press releases, data analysis, or statistics. The performance of these services may mean that such agents, both within and outside the EU/EEA, are able to gain access to your personal data. Companies that process personal data on our behalf must always affirm that they are GDPR compliant and sign a non-disclosure agreement with us so that we are able to ensure a high level of protection of your personal data even with our partners. If such a company reports a breach that may involve your personal data, we are required to report such a breach to you within 72 hours. Special safeguards are taken with regard to partners outside the EU/EEA, such as signing agreements that include the standardized model clauses for data transfers adopted by the EU Commission and which are available on the EU Commission’s Sites. We may also disclose your personal data to third parties, for example, the police or other public authorities, pursuant to a subpoena or other legal process, or if we are otherwise required to disclose such data by law or public authority decision. We will not disclose your personal data to any extent other than described in this section. #### g. Your Rights and the Right to File a Complaint Under applicable data protection legislation, you are entitled, at any time, to request access to the personal data that is processed about you, to have erroneous personal data corrected, to request that we stop processing and delete your personal data, to request that the processing of your personal data is restricted, to exercise your right to data portability, to withdraw consent to particular processing (where such consent has been obtained) and to object to the processing of your personal data. The aforementioned provision notwithstanding, the Company reserves the right to retain data as required by law by and through the usage of our services. In such an event, you may contact the Company via the contact details listed below. If you consider that your personal data has been processed in contravention of applicable data protection legislation or of these provisions, you may file a complaint with the applicable regulatory authority in your country or in the United Kingdom.   #### 3. Data Controller and Contact Details #### a. Data Controller For all purposes and unless otherwise specifically disclosed herein or to the customer or user, the data controller of this Site is Autheo LLC. #### b. Contact Details If you have any questions on how we process your personal data or want information about further contact details for the data controllers above, please contact us through this Site at [devsupport@autheo.com](mailto:devsupport@autheo.com)   ### 4. Miscellaneous Provisions #### a. Cookies The Company, in common with many web site operators, may use standard technology called “cookies” on its Sites. A cookie is a piece of data stored on a site visitor's hard drive to help us improve its access to our site and identify repeat visitors to our site. For instance, when we use a cookie to identify you, you would not have to log in a password more than once, thereby saving time while on our site. Cookies can also enable us to track and target the interests of our users to enhance their experience on our site. Usage of a cookie is in no way linked to any personally identifiable information. You can disable cookies by turning them off in your browser; however, some areas of the Sites may not function properly if you do so.  #### b. Acceptance of GDPR Policy By using this Site or any other Company or Affiliate Site or interactive banner ads, you represent that you are of legal age and signify your acceptance of our GDPR Policy, and you adhere to the terms and conditions posted on the Site. By submitting your information, you agree that it will be governed by our GDPR Policy. #### c. Amendments to this Policy This GDPR policy may be amended from time to time, in which case all registered users of the Sites will promptly be advised by email to their registered email addresses. Nevertheless, users are advised to periodically review the GDPR Policy of this Site to receive the latest information and advice as to privacy protections and processes. # General disclaimer Source: https://legal.autheo.com/legal-agreements/general-disclaimer 04/29/2025 Neither Autheo LLC, nor any of its affiliates or employees is an investment advisor or a broker-dealer. The information presented on any social media platform, including but not limited to, its Website, Twitter, Facebook, Medium or any other source of digital or social media is provided for informative purposes only and is not to be treated as a recommendation to make any specific investment. No such information, whether published by Autheo LLC , or any of its affiliates, spokespersons or representatives, constitutes advice or a recommendation. Any third-party opinions and analyses included in this document are based on information obtained from sources believed to be reliable and are provided “as is.” Autheo LLC, and/or its affiliates, spokespersons and/or representatives make no representation or warranty, whether express, implied, or statutory, as to the accuracy or completeness of such information, which may be subject to change without notice. *** © 2026 AUTHEO Legal \ \\ # Privacy policy Source: https://legal.autheo.com/legal-agreements/privacy-policy Your privacy is important to us. It is Autheo LLC's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, [https://www.autheo.com/](https://www.autheo.com/), and other sites we own and operate. Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service. In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site. #### Information We Collect Information we collect falls into one of two categories: “voluntarily provided” information and “automatically collected” information. “Voluntarily provided” information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions. “Automatically collected” information refers to any information automatically sent by your devices in the course of accessing our products and services. #### Log Data When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your device’s Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit. Additionally, if you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is. Please be aware that while this information may not be personally identifying by itself, it may be possible to combine it with other data to personally identify individual persons. #### Device Data When you visit our website or interact with our services, we may automatically collect data about your device, such as: Device type Operating system Unique device identifiers Device settings Geo-location data Data we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us. #### Personal Information We may ask for personal information — for example, when you subscribe to our newsletter or when you contact us — which may include one or more of the following: Name, Email, Social media profiles, Date of birth, Phone/mobile number, Home/mailing address, User-Generated Content. We consider “user-generated content” to be materials (text, image and/or video content) voluntarily supplied to us by our users for the purpose of publication, processing, or usage on our platform. All user-generated content is associated with the account or email address used to submit the materials. Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy. #### Transaction Data Transaction data refers to data that accumulates over the normal course of operation on our platform. This may include transaction records, stored files, user profiles, analytics data and other metrics, as well as other types of information, created or generated, as users interact with our services. Legitimate Reasons for Processing Your Personal Information We only collect and use your personal information when we have a legitimate reason for doing so. In which instance, we only collect personal information that is reasonably necessary to provide our services to you. #### Collection and Use of Information We may collect personal information from you when you do any of the following on our website: Register for an account Purchase a subscription Enter any of our competitions, contests, sweepstakes, and surveys Sign up to receive updates from us via email or social media channels Use a mobile device or web browser to access our content Contact us via email, social media, or on any similar technologies When you mention us on social media We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes: to provide you with our platform's core features and services to enable you to customize or personalize your experience of our website to deliver products and/or services to you to contact and communicate with you for analytics, market research, and business development, including to operate and improve our website, associated applications, and associated social media platforms for advertising and marketing, including to send you promotional information about our products and services and information about third parties that we consider may be of interest to you to consider your employment application to enable you to access and use our website, associated applications, and associated social media platforms for internal record keeping and administrative purposes to run competitions, sweepstakes, and/or offer additional benefits to you to comply with our legal obligations and resolve any disputes that we may have to attribute any content (e.g. posts and comments) you submit that we publish on our website for security and fraud prevention, and to ensure that our sites and apps are safe, secure, and used in line with our terms of use for technical assessment, including to operate and improve our app, associated applications, and associated social media platforms We may combine voluntarily provided and automatically collected personal information with general information or research data we receive from other trusted sources. For example, If you provide us with your location, we may combine this with general information about currency and language to provide you with an enhanced experience of our site and service. #### Security of Your Personal Information When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification. Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security. You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services. For example, ensuring any passwords associated with accessing your personal information and accounts are secure and confidential. #### How Long We Keep Your Personal Information We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you. However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes. #### Children’s Privacy We do not aim any of our products or services directly at children under the age of 13 and we do not knowingly collect personal information about children under 13. Disclosure of Personal Information to Third Parties We may disclose personal information to: a parent, subsidiary or affiliate of our company third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, debt collectors, maintenance or problem- solving providers, marketing or advertising providers, professional advisors, and payment systems operators our employees, contractors, and/or related entities our existing or potential agents or business partners sponsors or promoters of any competition, sweepstakes, or promotion we run credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights third parties, including agents or sub-contractors who assist us in providing information, products, services, or direct marketing to you third parties to collect and process data an entity that buys, or to which we transfer all or substantially all of our assets and business Third parties we currently use include: Google Analytics Email Newsletters Marketing Automation Google AdSense Bing Ads AdColony AppLovin Paypal Stripe Google Payments Apple Pay Your Rights and Controlling Your Personal Information Your choice: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our website or the products and/or services offered on or through it. Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us. #### Marketing Permission If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below. Access: You may request details of the personal information that we hold about you. #### Correction If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date. #### Non-Discrimination We will not discriminate against you for exercising any of your rights over your personal information. Unless your personal information is required to provide you with a particular service or offer (for example processing transaction data), we will not deny you goods or services and/or charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties, or provide you with a different level or quality of goods or services. #### Notification of Data Breaches We will comply with laws applicable to us in respect of any data breach. #### Complaints If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint. #### Unsubscribe To unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details provided in this privacy policy, or opt-out using the opt-out facilities provided in the communication. We may need to request specific information from you to help us confirm your identity. #### Use of Cookies We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified. Please refer to our Cookie Policy for more information. #### Business Transfers If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information. #### Limits of Our Policy Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices. #### Changes to This Policy At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy. If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy. If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information. #### Additional Disclosures for Australian Privacy Act Compliance (AU) ##### International Transfers of Personal Information Where the disclosure of your personal information is solely subject to Australian privacy laws, you acknowledge that some third parties may not be regulated by the Privacy Act and the Australian Privacy Principles in the Privacy Act. You acknowledge that if any such third party engages in any act or practice that contravenes the Australian Privacy Principles, it would not be accountable under the Privacy Act, and you will not be able to seek redress under the Privacy Act. #### Additional Disclosures for General Data Protection Regulation (GDPR) Compliance (EU) ##### Data Controller / Data Processor The GDPR distinguishes between organisations that process personal information for their own purposes (known as "data controllers") and organisations that process personal information on behalf of other organisations (known as "data processors"). We, Autheo LLC, located at the address provided in our Contact Us section, are a Data Controller with respect to the personal information you provide to us. #### Legal Bases for Processing Your Personal Information We will only collect and use your personal information when we have a legal right to do so. In which case, we will collect and use your personal information lawfully, fairly, and in a transparent manner. If we seek your consent to process your personal information, and you are under 16 years of age, we will seek your parent or legal guardian’s consent to process your personal information for that specific purpose. Our lawful bases depend on the services you use and how you use them. This means we only collect and use your information on the following grounds: #### Consent From You Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. You may consent to providing your name and contact details for the purpose of entering a giveaway or promotion. While you may withdraw your entry at any time, this will not affect any selection or judging that has already taken place. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy. #### Performance of a Contract or Transaction Where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, if you purchase a product, service, or subscription from us, we may need to use your personal and payment information in order to process and deliver your order. #### Our Legitimate Interests Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests. #### Compliance with Law In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. If you have any further enquiries about how we retain personal information in order to comply with the law, please feel free to enquire using the details provided in the Contact Us section of this privacy policy. #### International Transfers Outside of the European Economic Area (EEA) We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means. #### Your Rights and Controlling Your Personal Information Restrict: You have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests. #### Objecting to Processing You have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights, and freedoms, in order to proceed with the processing of your personal information. #### Data Portability You may have the right to request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party. #### Additional Disclosures for U.S. States Privacy Law Compliance The following section includes provisions that comply with the privacy laws of these states (California, Colorado, Delaware, Florida, Virginia, and Utah) and is applicable only to the residents of those states. Specific references to a particular state (in a heading or in the text) are only a reference to that state's law and applies only to that state's residents. Non-state specific language applies to all of the states listed above. #### Do Not Track Some browsers have a "Do Not Track" feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser "Do Not Track" signals. We adhere to the standards outlined in this privacy policy, ensuring we collect and process personal information lawfully, fairly, transparently, and with legitimate, legal reasons for doing so. #### Cookies and Pixels At all times, you may decline cookies from our site if your browser permits. Most browsers allow you to activate settings on your browser to refuse the setting of all or some cookies. Accordingly, your ability to limit cookies is based only on your browser’s capabilities. Please refer to the Cookies section of this privacy policy for more information. #### California Privacy Laws - CPPA Under California Civil Code Section 1798.83, if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may ask us about the information we release to other organizations for their marketing purposes. In accordance with your right to non-discrimination, we may offer you certain financial incentives permitted by the California Consumer Privacy Act, and the California Privacy Rights Act (collectively, CCPA) that can result in different prices, rates, or quality levels for the goods or services we provide. Any CCPA-permitted financial incentive we offer will reasonably relate to the value of your personal information, and we will provide written terms that describe clearly the nature of such an offer. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time. Under California Civil Code Section 1798.83, if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may ask us about the information we release to other organizations for their marketing purposes. To make such a request, please contact us using the details provided in this privacy policy with “Request for California privacy information” in the subject line. You may make this type of request once every calendar year. We will email you a list of categories of personal information we revealed to other organisations for their marketing purposes in the last calendar year, along with their names and addresses. Not all personal information shared in this way is covered by Section 1798.83 of the California Civil Code. #### California Notice of Collection In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA: For more information on information we collect, including the sources we receive information from, review the “Information We Collect” section. We collect and use these categories of personal information for the business purposes described in the “Collection and Use of Information” section, including to provide and manage our Service. #### Right to Know and Delete You have rights to delete your personal information we collected and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us: The categories of personal information we have collected about you; The categories of sources from which the personal information was collected; The categories of personal information about you we disclosed for a business purpose or sold; The categories of third parties to whom the personal information was disclosed for a business purpose or sold; The business or commercial purpose for collecting or selling the personal information; and The specific pieces of personal information we have collected about you. To exercise any of these rights, please contact us using the details provided in this privacy policy. #### Shine the Light In addition to the rights discussed above, you have the right to request information from us regarding the manner in which we share certain personal information as defined by applicable statute with third parties and affiliates for their own direct marketing purposes. To receive this information, send us a request using the contact details provided in this privacy policy. Requests must include “Privacy Rights Request” in the first line of the description and include your name, street address, city, state, and ZIP code. Additional Disclosures for UK General Data Protection Regulation (UK GDPR) Compliance (UK) #### Data Controller / Data Processor The GDPR distinguishes between organisations that process personal information for their own purposes (known as “data controllers”) and organizations that process personal information on behalf of other organizations (known as “data processors”). For the purposes covered by this Privacy Policy, we are a Data Controller with respect to the personal information you provide to us and remain compliant with our data controller obligations under GDPR. #### Third-Party Provided Content We may indirectly collect personal information about you from third-parties who have your permission to share it. For example, if you purchase a product or service from a business working with us, and give your permission for us to use your details in order to complete the transaction. We may also collect publicly available information about you, such as from any social media and messaging platforms you may use. The availability of this information will depend on both the privacy policies and your own privacy settings on such platforms. #### Additional Disclosure for Collection and Use of Personal Information In addition to the aforementioned purposes warranting the collection and use of personal information, we may also conduct marketing and market research activities, including how visitors use our site, website improvement opportunities and user experience. #### Personal Information No Longer Required for Our Purposes If your personal information is no longer required for our stated purposes, or if you instruct us under your Data Subject Rights, we will delete it or make it anonymous by removing all details that identify you (“Anonymisation”). However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes. #### Legal Bases for Processing Your Personal Information Data Protection and Privacy Laws permit us to collect and use your personal data on a limited number of grounds.. In which case, we will collect and use your personal information lawfully, fairly and in a transparent manner. We never directly market to any person(s) under 18 years of age. Our lawful bases depend on the services you use and how you use them. This is a non-exhaustive list of the lawful bases we use: #### Consent From You Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. When you contact us, we assume your consent based on your positive action of contact, therefore you consent to your name and email address being used so we can respond to your enquiry. Where you agree to receive marketing communications from us, we will do so based solely on your indication of consent or until you instruct us not to, which you can do at any time. While you may request that we delete your contact details at any time, we cannot recall any email we have already sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy. #### Performance of a Contract or Transaction Where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, if you contact us with an enquiry, we may require personal information such as your name and contact details in order to respond. #### Our Legitimate Interests Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests. #### Compliance with Law In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. For example, we are required to keep financial records for a period of 7 years. If you have any further enquiries about how we retain personal information in order to comply with the law, please feel free to enquire using the details provided in the Contact Us section of this privacy policy. #### International Transfers of Personal Information The personal information we collect is stored and/or processed in the United Kingdom by us. Following an adequacy decision by the EU Commission, the UK has been granted an essentially equivalent level of protection to that guaranteed under UK GDPR. On some occasions, where we share your data with third parties, they may be based outside of the UK, or the European Economic Area (“EEA”). These countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: we will perform those transfers in accordance with the requirements of the UK GDPR (Article 45) and Data Protection Act 2018; we will adopt appropriate safeguards for protecting the transferred data, including in transit, such as standard contractual clauses (“SCCs”) or binding corporate rules. #### Your Data Subject Rights Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests. #### Right to Object You have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights, and freedoms, in order to proceed with the processing of your personal information. #### Right to be Informed You have the right to be informed with how your data is collected, processed, shared and stored. #### Right of Access You may request a copy of the personal information that we hold about you at any time by submitting a Data Subject Access Request (DSAR). The statutory deadline for fulfilling a DSAR request is 30 calendar days from our receipt of your request. #### Right of Erasure In certain circumstances, you can ask for your personal data to be erased from the records held by organisations. However this is a qualified right; it is not absolute, and may only apply in certain circumstances. When may the right to erasure apply? When the personal data is no longer necessary for the purpose for which it was originally collected or processed for. If consent was the lawful basis for processing personal data and that consent has been withdrawn. Autheo LLC relies on consent to process personal data in very few circumstances. The Company is relying on legitimate interests as a legal basis for processing personal data and an individual has exercised the right to object and it has been determined that the Company has no overriding legitimate grounds to refuse that request. Personal data are being processed for direct marketing purposes e.g. a person’s name and email address, and the individual objects to that processing. There is legislation that requires that personal data are to be destroyed. #### Right to Portability Individuals have the right to get some of their personal data from an organisation in a way that is accessible and machine-readable, for example as a csv file. Associated with this, individuals also have the right to ask an organisation to transfer their personal data to another organisation. However, the right to portability: only applies to personal data which a person has directly given to Autheo LLC in electronic form; and onward transfer will only be available where this is “technically feasible”. #### Right to Rectification If personal data is inaccurate, out of date, or incomplete, individuals have the right to correct, update or complete that data. Collectively this is referred to as the right to rectification. Rectification may involve filling the gaps i.e. to have to have incomplete personal data completed – although this will depend on the purposes for the processing. This may involve adding a supplementary statement to the incomplete data to highlight any inaccuracy or claim thereof. This right only applies to an individual’s own personal data; a person cannot seek the rectification of another person’s information. #### Notification of Data Breaches Upon discovery of a data breach, we will investigate the incident and report it to the UK’s data protection regulator and yourself, if we deem it appropriate to do so. #### Complaints You have the right, at any time, to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues ([www.ico.org.uk](http://www.ico.org.uk)). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance using the details below. Please provide us with as much information as you can about the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. #### Enquiries, Reports, and Escalation To enquire about Autheo LLC's privacy policy, or to report violations of user privacy, you may contact our Data Protection Officer using the details in the Contact us section of this privacy policy. If we fail to resolve your concern to your satisfaction, you may also contact the Information Commissioner’s Office (ICO), the UK Data Protection regulator: Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF Tel: 0303 123 1113 (local rate) Website: [www.ico.org.uk](http://www.ico.org.uk) Additional Disclosures for Personal Information Protection and Electronic Documents Act (PIPEDA) Compliance (Canada) #### Additional Scope of Personal Information In accordance with PIPEDA, we broaden our definition of personal information to include any information about an individual, such as financial information, information about your appearance, your views and opinion (such as those expressed online or through a survey), opinions held about you by others, and any personal correspondences you may have with us. While this information may not directly identify you, be aware that it may be combined with other information to do so. As PIPEDA refers to personal information using the term Personally Identifying Information (PII), any references to personal information and PII in this privacy policy, and in official communications from Autheo LLC, are intended as equivalent to one another in every way, shape and form. #### Valid Consent Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. When you contact us, we assume your consent based on your positive action of contact, therefore you consent to your name and email address being used so we can respond to your enquiry. Under PIPEDA, consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose, and consequences of the collection, use, or disclosure of the personal information to which they are consenting. Where you agree to receive marketing communications from us, we will do so based solely on your indication of consent or until you instruct us not to, which you can do at any time. While you may request that we delete your contact details at any time, we cannot recall any email we have already sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy. #### International Transfers of Information While Autheo LLC endeavors to keep, store and handle customer data within locations in Canada, it may use agents or service providers located in the United States (U.S.), European Economic Area (EEA) or United Kingdom (UK) to collect, use, retain and process personal information as part of providing services to you. While we use all reasonable efforts to ensure that personal information receives the same level of security in any other jurisdiction as it would in Canada, please be aware that privacy protections under U.S. laws may not be the same adequacy. #### Customer Data Rights Although PIPEDA does not contain an extensive set of consumer rights, it does grant consumers the right to: Access the personal information organizations hold about them; Correct any inaccurate or outdated personal information the organization hold about them (or, if this is not possible, delete the inaccurate personal information) Withdraw consent for any activities for which they have consented (e.g. direct marketing or cookies #### Right to Withdraw Consent Although PIPEDA does not contain an extensive set of consumer rights, it does grant consumers the right to: Access the personal information organizations hold about them; Correct any inaccurate or outdated personal information the organization hold about them (or, if this is not possible, delete the inaccurate personal information) Withdraw consent for any activities for which they have consented (e.g. direct marketing or cookies #### Right of Access under PIPEDA PIPEDA gives you a general right to access the PII held by businesses subject to this law. Under PIPEDA, you need to make your access request in writing and pay a minimal fee of \$30.00. If any organizational fees seem unjust, you have the right to complain about this. We retain the right to decide how we disclose the copies of your PII to you. We will take all necessary measures to fulfill your request in 30 days from receipt, otherwise we must inform you of our inability to do so before the 30-day timeframe if: meeting the time limit would unreasonably interfere with our business activities; or the time required to undertake consultations necessary to respond to the request would make it impractical to meet the time limit. We can also extend the time limit for the length of time required to convert the personal information into an alternative format. In these circumstances, we will advise you of the delay within the first 30 days and explain the reason for it. #### Right of Rectification under PIPEDA You may request a correction to any factual errors or omissions within your PII. We would ask you to provide some evidence to back up your claim. Under PIPEDA, an organization must amend the information, as required, if you successfully demonstrate that it’s incomplete or inaccurate. You may contact us at any time, using the information provided in the Contact Us section of this privacy policy if you believe your PII on our systems is incorrect or incomplete. If we cannot agree on changing the information, you have the right to have your concerns recorded with the Office of the Privacy Commission of Canada. #### Compliance with PIPEDA’s Ten Principles of Privacy This privacy policy complies with the PIPEDA’s requirements and ten principles of privacy, which are as follows: * Accountability. Autheo LLC is responsible for the PII under its control and will designate one or more persons to ensure organizational accountability for compliance with the ten principles of privacy under PIPEDA, whose details are included below. All personnel are accountable for the protection of customers’ personal information. * Identifying purposes. Autheo LLC identifies the purposes for which personal information is collected at or before the time the information is collected. * Consent. Consent is required for Autheo LLC's collection, use or disclosure of personal information, except where required or permitted by PIPEDA or other law. In addition, when customers access a product or service offered by us, consent is deemed to be granted. Express consent may be obtained verbally, in writing or through electronic means. Alternatively, consent may be implied through the actions of customers or continued use of a product or service following Autheo LLC's notification of changes. * Limiting collection. Personal information collected will be limited to that which is necessary for the purposes identified by Autheo LLC. * Limiting use, disclosure and retention. We will not use or disclose personal information for purposes other than those for which the information was collected, except with your consent or as required by law. We will retain personal information only for as long as is necessary to fulfill the purposes for collecting such information and compliance with any legal requirements. * Accuracy. Personal information will be maintained by Autheo LLC in an accurate, complete and up-to-date format as is necessary for the purpose(s) for which the personal information was collected. * Safeguards. We will protect personal information with security safeguards appropriate to the sensitivity of such information. * Openness. We will make our policies and practices relating to the collection and management of personal information readily available upon request, including our brochures or other information that explain our policies, standards, or codes. * Customer access. We will inform customers of the existence, use and disclosure of their personal information and will provide access to their personal information, subject to any legal restrictions. We may require written requests for access to personal information and in most cases, will respond within 30 days of receipt of such requests. Customers may verify the accuracy and completeness of their personal information, and may request the personal information be corrected or updated, if appropriate. * Challenging compliance Customers are welcome to direct any questions or inquiries concerning our compliance with this privacy policy and PIPEDA requirements using the contact information provided in the Contact Us section of this privacy policy. #### Cookie Compliance Our email interactions with our customers are compliant with Canadian Anti-Spam Legislation. The Company does not send unsolicited email to persons with whom we have no relationship. We will not sell personal information, such as email addresses, to unrelated third-parties. On occasion, your personal information may be provided to our third-party partners to administer the products and services you request from us. When you leave our website by linking to another website, you are subject to the privacy and security policies of the new website. We encourage you to read the privacy policies of all websites you visit, especially if you share any personal information with them. Please refer to our Cookie Policy for more information. #### Enquiries, Reports, and Escalation To enquire about Autheo LLC's privacy policy, or to report violations of user privacy, you may contact us using the details in the Contact us section of this privacy policy. If we fail to resolve your concern to your satisfaction, you may also contact the Office of the Privacy Commissioner of Canada: 30, Victoria Street Gatineau, Quebec K1A 1H3 Toll Free: 1.800.282.1376 [www.priv.gc.ca](http://www.priv.gc.ca) #### Contact Us For any questions or concerns regarding your privacy, you may contact us using the following details: Autheo LLC Legal Team [legal@autheo.com](mailto:legal@autheo.com) # Terms of service Source: https://legal.autheo.com/legal-agreements/terms-of-service These Terms of Service govern your use of the website located at [https://www.autheo.com/](https://www.autheo.com/) and any related services provided by Autheo LLC. By accessing [https://www.autheo.com/](https://www.autheo.com/), you agree to abide by these Terms of Service and to comply with all applicable laws and regulations. If you do not agree with these Terms of Service, you are prohibited from using or accessing this website or using any other services provided by Autheo LLC. We, Autheo LLC, reserve the right to review and amend any of these Terms of Service at our sole discretion. Upon doing so, we will update this page. Any changes to these Terms of Service will take effect immediately from the date of publication. These Terms of Service were last updated on 19 October 2023. #### Limitations of Use By using this website, you warrant on behalf of yourself, your users, and other parties you represent that you will not: modify, copy, prepare derivative works of, decompile, or reverse engineer any materials and software contained on this website; remove any copyright or other proprietary notations from any materials and software on this website; transfer the materials to another person or "mirror" the materials on any other server; knowingly or negligently use this website or any of its associated services in a way that abuses or disrupts our networks or any other service Autheo LLC provides; use this website or its associated services to transmit or publish any harassing, indecent, obscene, fraudulent, or unlawful material; use this website or its associated services in violation of any applicable laws or regulations; use this website in conjunction with sending unauthorized advertising or spam; harvest, collect, or gather user data without the user’s consent; or use this website or its associated services in such a way that may infringe the privacy, intellectual property rights, or other rights of third parties. #### Intellectual Property The intellectual property in the materials contained in this website are owned by or licensed to Autheo LLC and are protected by applicable copyright and trademark law. We grant our users permission to download one copy of the materials for personal, non-commercial transitory use. This constitutes the grant of a license, not a transfer of title. This license shall automatically terminate if you violate any of these restrictions or the Terms of Service, and may be terminated by Autheo LLC at any time. #### User-Generated Content You retain your intellectual property ownership rights over content you submit to us for publication on our website. We will never claim ownership of your content, but we do require a license from you in order to use it. When you use our website or its associated services to post, upload, share, or otherwise transmit content covered by intellectual property rights, you grant to us a non-exclusive, royalty-free, transferable, sub-licensable, worldwide license to use, distribute, modify, run, copy, publicly display, translate, or otherwise create derivative works of your content in a manner that is consistent with your privacy preferences and our Privacy Policy. The license you grant us can be terminated at any time by deleting your content or account. However, to the extent that we (or our partners) have used your content in connection with commercial or sponsored content, the license will continue until the relevant commercial or post has been discontinued by us. You give us permission to use your username and other identifying information associated with your account in a manner that is consistent with your privacy preferences and our Privacy Policy. #### Liability Our website and the materials on our website are provided on an 'as is' basis. To the extent permitted by law, Autheo LLC makes no warranties, expressed or implied, and hereby disclaims and negates all other warranties including, without limitation, implied warranties or conditions of merchantability, fitness for a particular purpose, or non-infringement of intellectual property, or other violation of rights. In no event shall Autheo LLC or its suppliers be liable for any consequential loss suffered or incurred by you or any third party arising from the use or inability to use this website or the materials on this website, even if Autheo LLC or an authorized representative has been notified, orally or in writing, of the possibility of such damage. In the context of this agreement, "consequential loss" includes any consequential loss, indirect loss, real or anticipated loss of profit, loss of benefit, loss of revenue, loss of business, loss of goodwill, loss of opportunity, loss of savings, loss of reputation, loss of use and/or loss or corruption of data, whether under statute, contract, equity, tort (including negligence), indemnity or otherwise. Because some jurisdictions do not allow limitations on implied warranties, or limitations of liability for consequential or incidental damages, these limitations may not apply to you #### Accuracy of Materials The materials appearing on our website are not comprehensive and are for general information purposes only. Autheo LLC does not warrant or make any representations concerning the accuracy, likely results, or reliability of the use of the materials on this website, or otherwise relating to such materials or on any resources linked to this website. #### Links Autheo LLC has not reviewed all of the sites linked to its website and is not responsible for the contents of any such linked site. The inclusion of any link does not imply endorsement, approval or control by Autheo LLC of the site. Use of any such linked site is at your own risk and we strongly advise you make your own investigations with respect to the suitability of those sites. #### Right to Terminate We may suspend or terminate your right to use our website and terminate these Terms of Service immediately upon written notice to you for any breach of these Terms of Service. #### Severance Any term of these Terms of Service which is wholly or partially void or unenforceable is severed to the extent that it is void or unenforceable. The validity of the remainder of these Terms of Service is not affected. #### Governing Law These Terms of Service are governed by and construed in accordance with the laws of United States. You irrevocably submit to the exclusive jurisdiction of the courts in that State or location. # Privacy notice + KYC/AML Source: https://legal.autheo.com/node-sale-policies/privacy-kyc *Version 1.0 — Effective October 17, 2025* Contact: [legal@autheo.com](mailto:legal@autheo.com) • [https://www.autheo.com/nodesale](https://www.autheo.com/nodesale) ## Overview This Privacy Notice explains how Autheo LLC (“Autheo”, “we”, “us”) collects, uses, and shares personal information in connection with the Autheo Node Sale and validator operations. It also describes our identity and sanctions screening (KYC/AML) program. This Notice is incorporated by reference into the Node Sale Terms of Service and the Validator Node Purchase & License Agreement. ## Who we are Autheo LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. For privacy questions: [legal@autheo.com](mailto:legal@autheo.com). ## What we collect A) Account & transactional data * Contact details (name, email), wallet address(es), transaction metadata (timestamps, amounts, on-chain tx IDs), license tier, purchase history, support tickets. B) Technical data * Device/OS/browser info, IP address, approximate geolocation, pages viewed, referral URLs, and cookie identifiers (see “Cookies” below). C) KYC/AML data (via Blockpass) * Identity documents, selfies/biometrics (for liveness/anti-fraud checks), date of birth, nationality, address, sanctions/PEP screening results, and verification decision logs. * Collected and initially processed by our provider Blockpass; Autheo receives verification outcomes, risk flags, and artifacts required for compliance/audit. You must not submit someone else's data. If you represent an entity, you confirm authority to provide data for required officers/beneficial owners. ## Why we use your data (purposes and legal bases) * Contract performance: create/manage your account; process purchases and transfers; deliver validator onboarding and support. * Legal obligations: identity verification, sanctions screening, recordkeeping, responding to lawful requests. * Legitimate interests: protect the network and users (security monitoring, fraud prevention, abuse detection); product analytics to improve the sale experience. * Consent: optional marketing emails, non-essential cookies (where required). ## How we share data * Vendors/Processors: identity verification (Blockpass), cloud hosting, analytics, email delivery, customer support tools. Vendors act under contract and only process data on our instructions. * Legal/Compliance: regulators, law enforcement, or counterparties when required by law or to enforce our terms, protect users, or investigate fraud/abuse. * Corporate events: business transfers (merger, acquisition) subject to this Notice or a successor notice with comparable protections. We do not sell personal information. We do not share for cross-context behavioral advertising. ## KYC/AML statement * Mandatory verification. Purchase and transfer of a Node License require KYC and sanctions screening through Blockpass. * Sanctions screening. We screen against applicable sanctions/PEP lists. If screening fails or cannot be completed, Autheo may deny the transaction. * Automated decisions. Blockpass and Autheo may use automated checks to flag risk; humans review final outcomes where required. You may contact us to request a human review of a denial. * Retention for compliance. KYC/AML records are retained up to 7 years after your last transaction or account closure, or longer if required by law or to resolve disputes. ## Data retention * Account & transactional data: while your account is active and as needed for audits, tax, or legal claims (typically 7 years after last activity). * Technical logs: 90 days unless required for security investigations. * Marketing preferences: until you unsubscribe or request deletion. ## International transfers We operate in the United States. When personal data is transferred internationally, we use appropriate safeguards (e.g., Standard Contractual Clauses for EEA/UK data). ## Security We use administrative, technical, and physical safeguards proportionate to the data sensitivity, including encryption in transit, access controls, least-privilege practices, logging, and vendor due diligence. No system is perfectly secure. ## Your choices and rights * Access/rectify/delete your personal data. * Object or restrict certain processing (where applicable). * Portability of data you provided (where applicable). * Opt out of marketing at any time (unsubscribe link or email us). * Appeal an automated denial (contact [legal@autheo.com](mailto:legal@autheo.com)). ## Region-specific disclosures * EEA/UK: You have GDPR rights; Autheo is the controller for sale operations. Our legal bases are listed above. You may lodge a complaint with your local data protection authority. * California (CPRA): We do not sell or share personal information as defined by CPRA. You may exercise rights to know, delete, correct, and limit sensitive data use (subject to exceptions). To exercise rights, email [legal@autheo.com](mailto:legal@autheo.com). We may need to verify your request and identity. ## Cookies and analytics We use necessary cookies for security and session management, and (where permitted) optional analytics cookies to understand usage. You can manage preferences via your browser or our cookie banner. Disabling some cookies may affect site functionality. ## Children The Node Sale is not directed to anyone under 18. We do not knowingly collect personal data from children. ## Links and third-party sites Third-party sites and tools are governed by their own policies. We are not responsible for their practices. ## Updates to this notice We may update this Notice from time to time. The “Effective” date above will change when updates are posted. Material changes will be highlighted on the Sale Site. # Risk notice Source: https://legal.autheo.com/node-sale-policies/risk-notice *Version 1.0 — Effective October 17, 2025* Contact: [legal@autheo.com](mailto:legal@autheo.com) • [https://www.autheo.com/nodesale](https://www.autheo.com/nodesale) ## Purpose This Risk Notice summarizes material risks associated with purchasing, holding, transferring, operating, or delegating an Autheo validator node license. It is a readable counterpart to Exhibit E of the Validator Node Purchase & License Agreement and is incorporated by reference into the Node Sale Terms of Service. It is not exhaustive. ## Protocol and software risks Public blockchains, validator clients, and their dependencies may contain defects or vulnerabilities. Required upgrades or hotfixes can introduce regressions or change validator duties and hardware needs. ## Network and operations risks Congestion, partitions, DDoS, or peer misbehavior can impair performance or prevent participation. Power, ISP, cloud, or hardware failures can cause downtime or data loss. Poor time synchronization can degrade performance and increase penalties. ## Key management and security risks Theft, loss, or misuse of private keys can lead to double-signing, slashing, or permanent loss. Misconfigurations (including duplicate validators or unsafe failover) may trigger penalties. Backups can be corrupted; recovery procedures may fail if not tested. ## Slashing, penalties, and economic risks Consensus faults (including equivocation and double-signing) may lead to on-chain penalties such as slashing or jailing. Downtime and missed duties reduce rewards. No APR/APY, price, liquidity, or financial outcome is promised. Token markets are volatile. ## Governance and policy risks Governance may adjust emissions, fees, security thresholds, upgrade cadence, or other parameters on a forward-looking basis. Emergency actions (such as hotfixes or temporary halts) may be taken to preserve network security and can affect validator operations and economics. ## Regulatory, sanctions, and tax risks Laws and regulations applicable to validators, tokens, sanctions, AML, data, and privacy may change. Transactions or distributions may be paused, withheld, or denied to comply with sanctions or legal obligations. You are solely responsible for all tax reporting and payments. ## Third-party and supply-chain risks Validators rely on third-party providers and open-source software, including ISPs, cloud platforms, HSMs, remote signers, monitoring tools, and OS packages. These may fail, degrade, change terms, or be discontinued. ## Transaction finality and irreversibility On-chain transactions are generally irreversible. Errors in addresses, fees, contract interactions, or key handling can result in permanent loss. Chain reorganizations or contentious forks may require reconfiguration and operational decisions. ## Privacy and data risks Network metadata and telemetry can reveal patterns about infrastructure. Personal data submitted for eligibility or compliance is handled per the Autheo Privacy Notice; no system can guarantee absolute security. ## No advice; independent assessment Autheo does not provide investment, legal, or tax advice and does not act as a fiduciary. You should conduct independent due diligence and obtain professional advice as needed. ## Operator responsibilities You are responsible for secure operation, timely patching, monitoring, and incident response consistent with the Technical and Uptime Requirements (Exhibit B). Suspected key compromise, double-sign events, or major misconfigurations should be reported promptly using the channels Autheo designates. ## Assumption of risk By participating in the node sale or operating a validator, you acknowledge and accept the foregoing risks and those inherent to decentralized systems, and you agree that any emissions or rewards are governed solely by protocol logic and Exhibit C. ## Updates Autheo may update this Risk Notice to reflect new information, security guidance, or regulatory developments. The effective date above will be adjusted when updates occur. # Exhibit A — License scope and delivery Source: https://legal.autheo.com/node-sale-purchase/exhibit-a *Version 1.0 — Effective November, 2025* ## Scope of license Autheo grants the purchaser a limited, revocable, non-exclusive license to operate one validator for the Autheo blockchain in accordance with Autheo's published validator specifications and security standards, or to delegate operation to an Autheo-approved validator service where permitted by protocol rules. The license confers use rights only and does not grant equity, debt, or profit rights. ## License signifier Autheo may represent the license with a tokenized credential or NFT signifier recorded to the purchaser's designated wallet. The signifier evidences license status and acceptance of the Agreement and Exhibits; by itself, it does not convey corporate or investment rights and has no guaranteed monetary value. ## Delivery 1. Completion event. Delivery is complete when Autheo (a) records the license to the purchaser's designated wallet and (b) provides validator onboarding materials, which may include key-generation guidance, certificate-signing workflows, endpoint registration, and initial configuration instructions. 2. Timing. Autheo will use commercially reasonable efforts to complete delivery following cleared payment and successful compliance checks. 3. Activation. The purchaser must complete any required onboarding steps before producing validator duties on testnet or mainnet, as applicable. ## Purchaser responsibilities 1. Wallet and keys. Maintain sole custody and security of wallets, credentials, and recovery phrases; Autheo cannot recover lost keys. 2. Operations. Operate or delegate the validator in accordance with Exhibit B, including patching, monitoring, and incident response. 3. Contact and wallet record. Keep current contact details and the designated wallet address on file with Autheo; promptly update upon any change. 4. Notices and updates. Monitor Autheo release notes, advisories, and emergency directives and apply required changes within stated timelines. ## Delegation option Where delegation is permitted, the purchaser may appoint an Autheo-approved validator service to operate on the purchaser's behalf. The purchaser remains responsible for compliance with the Agreement and Exhibits, including any key custody retained by the purchaser, tax obligations, and adherence to sanctions/eligibility rules. ## Governance and network changes Validator duties, thresholds, client versions, and economic parameters may evolve through protocol governance or Autheo emergency actions required for network safety. Continued use after such changes constitutes acceptance. Autheo will provide reasonable notice for non-emergency changes. ## Transfer; KYC/OFAC Any change of holder must follow the transfer workflow in Exhibit D, including identity and sanctions screening through Autheo's designated provider (currently Blockpass) and payment of any applicable transfer admin fee. Movement of a signifier token without registry update does not transfer operating rights. ## Non-investment; No profit promise The license is a right to use network infrastructure. It is not an investment contract and does not include a promise of profits, price appreciation, or dividends. Any emissions or rewards are governed solely by Exhibit C and protocol logic. ## Suspension and termination Autheo may suspend or terminate license use rights for material breach of the Agreement or Exhibits, unlawful use, or to address emergent threats to network integrity, following notice and, where practicable, a reasonable opportunity to cure. ## Survival Purchaser responsibilities regarding key security, compliance, incident reporting, and any accrued obligations survive suspension, termination, or transfer to the extent applicable. # Exhibit B — Technical and uptime requirements Source: https://legal.autheo.com/node-sale-purchase/exhibit-b *Version 1.0 — Effective November 20, 2025* ## Scope and intent These requirements establish a practical baseline for operating an Autheo validator that safeguards network security and liveness without creating technical defaults for good-faith operators. Reasonable maintenance and force-majeure events are accounted for. ## Minimum system profile a) Compute and storage. Enterprise-grade CPU, sufficient RAM for active chain state, and NVMe SSD sized for projected 12-month growth plus 25% headroom. b) Network. Stable connectivity with a static or reserved IP, properly configured firewall/NAT, and upstream bandwidth and latency sufficient for consensus and gossip. c) Operating system. A currently supported 64-bit Linux distribution with timely security updates, hardened per common benchmarks. d) Key custody. Hardware security module, secure enclave, or equivalent isolated signing (including remote signer) strongly recommended for validator keys. e) Time sync. NTP or equivalent time service must be enabled and healthy. ## Software currency and patching a) Critical patches. Apply Autheo-designated critical security patches within 72 hours of notice. b) Routine updates. Apply non-critical, recommended client releases within 7 days of notice. c) Emergency directives. For a confirmed exploit or network instability, Autheo may issue an emergency directive with a shorter timeline; operators should make best efforts to comply promptly. ## Uptime target and measurement a) Target. Monthly validator uptime target is 99.5%. b) Measurement. Uptime is measured by Autheo telemetry against the validator’s expected participation, including proposals, attestations, and commits as applicable. c) Exclusions. The following are excluded from uptime calculations: i) Planned maintenance up to 8 hours per calendar month with at least 24 hours advance notice via the operator’s designated channel or dashboard; ii) Force majeure events (regional power or ISP outages, natural disasters, widespread cloud provider incidents) outside the operator’s reasonable control; iii) Autheo-directed maintenance or upgrades; iv) Protocol-level incidents outside the operator’s control. d) Cure window. A single month below target does not constitute a breach if the operator implements reasonable remediation. Two consecutive months below target may require a corrective action plan; suspension is a last resort after notice and failure to cure. ## Slashing and safety controls a) Double-sign prevention. Operators must use configurations and tooling intended to prevent double signing, such as sentry/validator architecture, quorum checks, and safe key migrations. b) Incident reporting. Suspected key compromise, double signing, or major misconfiguration must be reported to Autheo within 24 hours, with a mitigation plan. c) Recovery. Operators should maintain tested procedures for key rotation and machine failover. ## Monitoring and logging a) Telemetry. Enable standard metrics and health probes for liveness, peer count, consensus participation, and resource utilization. b) Alerts. Configure alerts for process health, disk exhaustion, time drift, missed duties, and version skew. c) Retention. Maintain relevant logs and metrics for at least 90 days for incident analysis. Autheo may request excerpts for network security investigations. ## Change management a) Grace periods. Autheo may update technical requirements to address security or performance. Unless designated critical or emergency, operators will have a reasonable grace period to comply. b) Compatibility. Operators should avoid untested kernel, driver, or client changes that could impair consensus participation. ## Acceptable architectures a) Sentry pattern. Use of public sentry nodes in front of a private validator is recommended to reduce attack surface. b) Cloud or on-premises. Either is acceptable provided the security baseline, key custody, and uptime targets are met. Provider diversity for redundancy is encouraged. ## Compliance and enforcement a) Good-faith standard. Autheo will apply these requirements in good faith, considering operator evidence of reasonable diligence. b) Progressive steps. If material non-compliance persists after notice and a reasonable cure period, Autheo may take proportionate steps permitted by the Agreement, up to temporary suspension to protect network integrity. c) No waiver of risk. Meeting these requirements does not eliminate protocol-level risks or penalties imposed by on-chain rules. ## Documentation and contact Operators must keep current contact details on file and maintain an internal runbook covering deployment, upgrades, failover, and incident response. Autheo may distribute advisories and release notices through designated channels; operators are responsible for monitoring them. # Exhibit C — Emissions and rewards mechanics Source: https://legal.autheo.com/node-sale-purchase/exhibit-c *Version 1.0 — Effective November 20, 2025* ## Scope This Exhibit defines the validator emissions pool, schedule, and allocation. It does not promise any APR/APY or financial outcome. ## Pool and schedule 7.5% of the 7,000,000,000 THEO supply (525,000,000 THEO) is allocated to validator emissions, released linearly over seven (7) years. ## Allocation (baseline only at launch) For each reward window, the protocol distributes that window’s time-slice of emissions pro rata by License Weight among Active Validators: Sovereign = 1.0; Prime = 0.1; Core = 0.01. An Active Validator is a license recognized by the protocol in the applicable window, not suspended or jailed, and correctly configured for payouts. ## Future incentives (prospective; not guaranteed) Autheo may in the future introduce separate, discretionary incentive programs (including a performance-based pool) funded outside the 7.5% validator emissions pool. Any such program will (i) apply prospectively only, (ii) be subject to governance, and (iii) include published eligibility criteria (which may be tier-specific, such as Sovereign-only). These programs do not alter or reduce the baseline allocation above. ## Method of distribution Distributions occur at protocol-defined intervals to each validator's configured address; accounting is on-chain. The protocol may batch or delay distributions for upgrades or incident response without changing cumulative entitlement for unaffected periods. ## Penalties and withholds Protocol-level faults (for example, double-signing) may result in on-chain penalties. Material breaches of Exhibit B may result in rewards being reduced or withheld for impacted windows, in addition to protocol penalties. Distributions may be paused or withheld to comply with sanctions or other legal obligations. ## Illustrations and disclaimers Any figures in dashboards or calculators are illustrative only. Actual amounts vary with network conditions and participation. No APR/APY or profit is promised. ## Governance changes Governance may adjust parameters prospectively to preserve security and sustainability; previously accrued amounts are unaffected. # Exhibit D — Transfer and secondary policy Source: https://legal.autheo.com/node-sale-purchase/exhibit-d *Version 1.0 — Effective November 20, 2025* ## Scope This Exhibit governs any secondary transfer of an Autheo validator license across all tiers: Sovereign (full node), Prime (10% fractional license), and Core (1% fractional license). It ensures the validator license registry stays accurate, the transferee is bound to the Agreement and all Exhibits, and Autheo satisfies compliance obligations. ## Transfer method 1. Registry update required. A validator license may be transferred only through Autheo's approved transfer workflow that updates the validator license registry. 2. Token signifier. Movement of any tokenized signifier alone does not transfer operating rights. Until the registry shows the new holder, the current holder remains responsible for all obligations. 3. Binding effect. Completion of the registry update binds the transferee to the Agreement and all Exhibits as of the effective transfer time. ## Eligibility; KYC/OFAC 1. Mandatory verification. For each transfer event, both transferor and transferee must complete identity and sanctions screening through Autheo's designated provider (currently Blockpass). 2. Prohibited users. Autheo will deny or void transfers involving prohibited persons, entities, or jurisdictions, or where verification cannot be satisfactorily completed. ## Transfer admin fee 1. Fee schedule. A non-refundable administrative fee is payable at submission of the transfer request, per license transferred: a) Sovereign (full node): US\$150 b) Prime (10% fractional): US\$100 c) Core (1% fractional): US\$50 2. Dual-price protection. Autheo may offer a token-denominated option: US\$ amounts above or 50 THEO, whichever is higher at the time of request. 3. Who pays. The initiator of the transfer request pays the fee unless the parties agree otherwise between themselves. 4. Purpose. The fee covers administrative processing, compliance screening, and registry updates; it is not a resale royalty or trading fee. ## Waivers and reductions 1. Launch liquidity. For the first 90 days after mainnet launch, Autheo may waive or reduce the fee to as low as US\$50 per transfer to support healthy secondary liquidity. 2. Intra-group housekeeping. Transfers among a parent and its wholly owned subsidiaries may be reduced to US$0–US$50 at Autheo’s discretion upon proof of control. 3. Case-by-case discretion. Autheo may waive or adjust fees to correct operational errors or facilitate security-driven rekeying. ## Process and timing 1. Submission. The proposed transferee connects a compatible wallet, completes KYC/OFAC, and the transferor confirms release of the license. 2. Review window. Autheo targets review within 5 business days after complete materials are received; complex reviews may take longer. 3. Effective time. The transfer is effective only when the registry shows the transferee as the current holder; Autheo will issue confirmation via the sale interface or email. ## Technical re-provisioning 1. Keys and endpoints. Where required, the transferee completes any key or endpoint re-provisioning per Autheo onboarding before operating the validator. 2. Cool-down. Autheo may impose a brief cool-down to prevent double-sign risk during handover. ## Restrictions 1. No unauthorized splits. Sublicensing, fractionalization beyond defined tiers, or splitting license rights without Autheo’s written consent is void. 2. No encumbrances without consent. Licenses may not be pledged or otherwise encumbered in a way that would transfer rights upon default without Autheo’s transfer process and approvals. 3. Anti-evasion. Attempts to circumvent this Exhibit, including off-book assignments, are voidable and may result in suspension. ## Misstatements; Non-compliance Autheo may suspend or reverse a transfer that relied on material misstatements or that violates this Exhibit, applicable law, or sanctions restrictions. If reversal is not feasible, Autheo may suspend operating rights until a compliant transfer is completed. ## Records; Privacy Autheo will maintain records of transfer requests and outcomes. Personal data collected for transfer processing is handled per the Autheo Privacy Notice and used for compliance screening and audit purposes. # Exhibit E — Risk disclosures Source: https://legal.autheo.com/node-sale-purchase/exhibit-e *Version 1.0 — Effective November 20, 2025* ## Scope This Exhibit summarizes material risks associated with purchasing a validator license and operating or delegating a validator on the Autheo network. It is not exhaustive. By proceeding, you acknowledge and accept these risks and those inherent to decentralized systems. ## Protocol and software risks 1. Defects and exploits. Validator, client, and dependency code may contain undiscovered bugs or vulnerabilities that could result in downtime, slashing, or loss of funds. 2. Upgrades and regressions. Mandatory or emergency upgrades can introduce regressions or change validator duties and hardware requirements. 3. Dependency stack. Consensus clients, databases, libraries, operating systems, and drivers are third-party components that can fail or conflict. ## Network and operations risks 1. Liveness issues. Congestion, network partitions, DDoS, or peer misbehavior can impair performance or prevent participation. 2. Infrastructure failures. Power, ISP, cloud, or hardware failures can cause missed duties or data loss. 3. Time sync and clock drift. Poor timekeeping can degrade performance and increase slash risk. 4. Force majeure. Natural disasters, regional outages, and widespread platform incidents may disrupt service. ## Key management and security risks 1. Key compromise. Theft, leakage, or misuse of validator keys can cause double-signing, slashing, or permanent loss. 2. Operational error. Misconfigurations (e.g., running duplicate validators, unsafe failover) can trigger penalties. 3. Backup and recovery. Corrupt or incomplete backups, or flawed recovery procedures, can prolong downtime or lead to inconsistent state. ## Slashing, penalties, and economic risks 1. Protocol penalties. Equivocation, double-signing, and other consensus faults may result in slashing, jailing, or reward forfeiture. 2. Performance impact. Downtime, missed attestations/blocks, and version skew reduce rewards for affected periods. 3. Variable outcomes. Emissions and fees are determined by protocol logic and may change via governance. No APR/APY, price, or liquidity is promised. 4. Market volatility. Token markets are volatile; prices can move rapidly and unpredictably. ## Governance and policy risks 1. Parameter changes. Governance may adjust emissions, fees, security thresholds, upgrade cadence, or other parameters on a forward-looking basis. 2. Emergency actions. Autheo or governance may take emergency actions (e.g., hotfixes, temporary halts, accelerated upgrades) to preserve network security, which can affect validator duties and economics. ## Regulatory, sanctions, and tax risks 1. Legal uncertainty. Laws and regulations applicable to validators, tokens, staking, data, and privacy may change and could affect your eligibility or obligations. 2. Sanctions and KYC. Transfers and distributions may be paused, withheld, or denied if required to comply with sanctions, identity verification, or other legal obligations. 3. Tax treatment. You are solely responsible for tax reporting and payments; tax outcomes vary by jurisdiction and may change. ## Third-party and supply-chain risks 1. Providers and vendors. ISPs, cloud platforms, HSMs, remote signers, and monitoring services may fail, degrade, or change terms. 2. Open source. Third-party open-source software is provided under its own licenses and without warranties; maintainers may discontinue support. ## Transaction finality and irreversibility 1. Permanent effects. On-chain transactions are generally irreversible. Errors in addresses, fees, or contract interactions can result in permanent loss. 2. Forks. Chain reorganizations or contentious forks may alter historical records or validator sets, requiring reconfiguration and operational decisions. ## Privacy and data risks 1. Metadata exposure. Network and operational telemetry can reveal infrastructure patterns or locations. 2. Data handling. Personal data submitted for compliance is handled per the Autheo Privacy Notice; any breach at a third-party provider may expose such data despite reasonable safeguards. ## No fiduciary duties; Limited remedies 1. No advisory role. Autheo does not act as your advisor or fiduciary; you must conduct independent due diligence. 2. Limited remedies. To the maximum extent permitted by law, your remedies are limited as described in the Agreement; Autheo is not liable for indirect or consequential damages arising from the above risks. ## Operator responsibilities 1. Continuous diligence. You are responsible for secure operation, timely patching, monitoring, and incident response consistent with Exhibit B. 2. Incident reporting. You must promptly report suspected key compromise, double-sign events, or major misconfigurations and follow mitigation steps. 3. Compliance. You must satisfy ongoing eligibility requirements, including KYC/OFAC screening where applicable. ## Assumption of risk and acknowledgment By purchasing, holding, transferring, operating, or delegating a validator license, you represent that you understand and accept the foregoing risks; that you have the technical ability or qualified assistance to operate securely; and that you are not relying on any promise of profit, price appreciation, or specific financial outcome. # Exhibit F — Referral and promotions terms Source: https://legal.autheo.com/node-sale-purchase/exhibit-f *Version 1.0 — Effective November 20, 2025* ## Scope This Exhibit governs Autheo referral codes, promotional discounts, rebates, token rewards, and similar offers tied to validator license purchases across Sovereign, Prime, and Core tiers. It applies in addition to the Agreement and the Node Sale Terms of Service. ## Definitions * **Qualified Purchase** means a completed validator license purchase that clears payment, passes KYC/OFAC, is not refunded or charged back, and complies with these terms. * **Referrer** means a participant with a valid Autheo-issued referral code or link. * **Referred Purchaser** means a new purchaser who completes a Qualified Purchase using a valid code or link. * **Campaign Rules** means the public details Autheo publishes for a specific promotion (reward type, amount/percent, discount, dates, caps, tier limits, payout timing, any forms). * **Promo Participation** means meeting the promotion's eligibility conditions (e.g., KYC/OFAC, using a valid code, tier limits) for the sole purpose of that promotion. Promo Participation is distinct from validator “participation” used elsewhere in the Agreement. ## Eligibility Promo Participation requires KYC/OFAC and compliance with applicable laws. Autheo may exclude jurisdictions or user categories where a promotion is not lawful or feasible. Codes are non-transferable, may be disabled at any time, and are void where prohibited. ## Attribution and tracking Attribution is determined by the sale interface using the entered code or referral link. Unless Campaign Rules state otherwise: (i) **one code per order**; (ii) **non-stackable** with other codes; (iii) the **last valid code** at checkout governs. Autheo's records control in case of dispute. ## Reward types Campaigns may offer purchaser discounts at checkout, referrer rebates, token allocations, credits, or other incentives specified in the Campaign Rules. Unless stated otherwise, referrer rewards accrue only on **Qualified Purchases** and only for the tier(s) listed in the Campaign Rules. Percentages, amounts, and eligibility for any promotion are set in the **Campaign Rules** for that promotion and may be changed **prospectively** without amending this Exhibit. ## Caps and limits Autheo may set caps per referrer, per code, per tier, per purchaser, and per campaign. Caps may be quantity-based or value-based. Once a cap is reached, later purchases are ineligible for that campaign. ## Payouts and timing If applicable, referrer rewards are typically issued within the period stated in the Campaign Rules (default: within 30 days after the applicable refund/chargeback window closes), subject to successful KYC/OFAC and compliance checks. Autheo may batch or delay payouts to address upgrades or security incidents without changing the underlying entitlement for unaffected transactions. ## Fraud, misuse, and prohibited conduct Self-referrals, circular referrals, coupon scraping, spam, misrepresentation, resale of codes, and attempts to game or automate referrals are prohibited. Autheo may suspend codes, void rewards, and disqualify participants who engage in or benefit from prohibited conduct. ## Clawbacks and adjustments Autheo may cancel, refuse, or claw back unpaid rewards if the underlying purchase is refunded, reversed, fraudulent, fails compliance, or violates these terms. If a reward was already delivered and later found ineligible, Autheo may offset against future rewards or request repayment. ## Taxes Participants are solely responsible for any taxes arising from discounts, rebates, or rewards. Autheo may require tax forms where applicable. ## Compliance and sanctions Rewards and discounts will not be issued where doing so would violate sanctions, AML, or other legal requirements. Additional verification may be required. ## Relationship to purchase price Promotions do not change the underlying license price except as expressly stated in Campaign Rules. Discounts apply at checkout; rebates or token rewards apply after a Qualified Purchase and are **not guaranteed** until issued. ## Program changes and termination Autheo may modify, suspend, or terminate any promotion prospectively at any time. Changes will not retroactively remove valid, already-earned rewards, except where necessary to address fraud, legal non-compliance, or material system error. ## Data and privacy Autheo processes personal data related to promotions in accordance with the Autheo Privacy Notice, including for eligibility checks, payout processing, compliance, and audit. ## Publicity Autheo may list top referrers or publish anonymized campaign statistics. Individual identities will not be disclosed without consent unless required by law. ## Disputes Autheo's determination on eligibility, attribution, caps, and payout calculations is final, acting reasonably and in good faith. Disputes are resolved under the Agreement's governing law and dispute resolution terms. ## Survival Obligations regarding clawbacks, taxes, compliance, data handling, and dispute resolution survive the end of any particular campaign. ## Incorporation by reference The then-current **Campaign Rules** for each promotion are incorporated into this Exhibit by reference. In case of conflict, specific Campaign Rules for that promotion control over this Exhibit, except where doing so would violate law or sanctions requirements. # Exhibit G — Hosting and delegation policy Source: https://legal.autheo.com/node-sale-purchase/exhibit-g *Version 1.0 — Effective November 20, 2025* ## Scope Describes self-hosting vs. managed hosting options for Sovereign, Prime, and Core validator licenses. ## Approved providers Autheo may publish a non-exhaustive list (e.g., Zeeve, InfStones). Listing is informational and may change without notice. ## Costs Hosting fees are paid by the license holder directly to the provider. Any fee ranges published by Autheo are illustrative and not quotes. ## Onboarding Autheo will publish non-binding specs and runbooks for self-hosting; these do not modify Exhibit B. ## Compliance KYC/OFAC and jurisdictional restrictions may apply to hosting choices and payout routing. ## Security and keys Purchaser retains sole responsibility for key custody and validator safety (even when using a provider). ## Service changes Providers may change pricing/terms; Purchaser is responsible for monitoring, renewals, and migrations. # License agreement (1.0) Source: https://legal.autheo.com/node-sale-purchase/license-agreement *Version 1.0 — Effective November 20, 2025* Autheo LLC — 30 N Gould St Ste R, Sheridan, WY 82801, USA Contact: [legal@autheo.com](mailto:legal@autheo.com) • [autheo.com/nodesale](https://www.autheo.com/nodesale) ## 1. Parties; Purpose This Agreement (“Agreement”) is between Autheo LLC (“Autheo,” “we”) and the purchaser identified at checkout (“Purchaser,” “you”). It governs the purchase and use of an Autheo validator node license (“Node License”). ## 2. Agreement structure This Agreement incorporates the Exhibits listed in Section 17 and the site policies and TOS listed in Section 16. If there is a conflict: this Agreement → Exhibits → Node Sale TOS → site policies (Section 18). ## 3. Sale; No custody Purchases occur via smart-contract checkout. Autheo is not a broker or exchange and does not custody user assets. Transactions are on-chain and final (except as expressly stated herein). 3A. Non-Investment; No Profit Promise The License is a right to operate network infrastructure. It is not equity, debt, or an investment contract, and no rate of return, APR/APY, profit, price appreciation, or liquidity is promised or guaranteed. Any figures or calculators are illustrative only and non-binding. ## 4. Delivery and activation Delivery and activation are governed by Exhibit A (License Scope & Delivery). Delivery is complete when Autheo records the license to your designated wallet and provides onboarding materials; you must complete onboarding before producing validator duties. ## 5. Hosting fees and providers A node purchaser can either self-host or elect to use a node managed hosting provider, such as Infstones or Zeeve. If Purchaser elects managed hosting, Purchaser enters a separate agreement directly with the provider and is solely responsible for all fees associated with such provider. Provider pricing and service terms are set by the provider and may change without notice. Any hosting information or ranges disclosed by Autheo are informational only, do not modify this Agreement, and are not promises or quotations. Autheo is not a party to any hosting agreement and disclaims responsibility for provider performance, availability, or pricing. ## 6. Eligibility; KYC/OFAC Purchase and transfer require identity and sanctions screening through Autheo's provider (currently Blockpass). Autheo may deny a transaction if verification cannot be satisfactorily completed or would violate law. See Exhibit D and the Privacy Notice + KYC/AML Statement ([https://www.autheo.com/nodesale/privacy](https://www.autheo.com/nodesale/privacy)). ## 7. Wallets and security You are solely responsible for wallet security (including seed phrase, device integrity, and any HSM/remote signer choices). Autheo cannot recover lost keys. ## 8. Technical and uptime requirements Operation of a Node License is subject to Exhibit B (Technical and Uptime Requirements), including a 99.5% monthly uptime target with reasonable exclusions, 72h critical patch and 7d routine patch timelines, and 90-day log retention. Informative Materials (non-binding). Autheo may publish non-binding operator guides, runbooks, or checklists (e.g., an “Operator Checklist”) for convenience. These do not modify Exhibit B or impose additional obligations; Exhibit B controls if there is any conflict. ## 9. Emissions and rewards Validator emissions are determined solely by protocol logic as described in Exhibit C (Emissions & Rewards Mechanics). No APR/APY, price, or profit is promised or guaranteed. Autheo commits only to the emissions set forth in Exhibit C; no other token distributions are promised. Distributions occur at protocol-defined intervals to the configured payout address, and are subject to the validator remaining Active and compliant and the protocol producing rewards. ## 10. Transfers; Secondary market Transfers must use Autheo's registry update flow and comply with Exhibit D (Transfer & Secondary Policy), including KYC for every transfer and the posted admin fee schedule. ## 11. Prohibited use; Compliance You confirm you are not in a comprehensively sanctioned jurisdiction and are not a prohibited person. You must comply with applicable laws, export controls, and sanctions. ## 12. Third-party components Validators rely on third-party software, networks, and services. Such components are provided under their own licenses and terms. ## 13. Risk disclosures You acknowledge the risks summarized in Exhibit E (Risk Disclosures) and the Risk Notice ([https://www.autheo.com/nodesale/risk](https://www.autheo.com/nodesale/risk)). Blockchain transactions are irreversible; keys may be lost; networks may fork or degrade. THIS SUMMARY DOES NOT LIMIT THE DETAILED RISK DISCLOSURES IN EXHIBIT E. ## 14. Warranties; Disclaimers THE NODE LICENSE, MATERIALS, AND SALE SITE ARE PROVIDED “AS IS” AND “AS AVAILABLE.” AUTHEO DISCLAIMS ALL WARRANTIES TO THE MAXIMUM EXTENT PERMITTED BY LAW. ## 15. Limitation of liability TO THE MAXIMUM EXTENT PERMITTED BY LAW, AUTHEO WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES. AUTHEO’S AGGREGATE LIABILITY RELATING TO A NODE LICENSE IS CAPPED AT THE AMOUNTS YOU PAID TO AUTHEO FOR THAT LICENSE. ## 16. Indemnity You will defend, indemnify, and hold harmless Autheo and its personnel from third-party claims arising from your breach, negligence, willful misconduct, or unlawful use. ## 17. Incorporation by reference (live cross-references) The following documents (the “Site Policies”) are incorporated into this Agreement by reference and are available via the Autheo Node Sale landing-page footer at autheo.com (as updated from time to time): 1. Node Sale Terms of Service; 2. Risk Notice; 3. Privacy Notice + KYC/AML Statement; 4. Transfer & Secondary Policy; and 5. Slashing & Uptime Policy is expressly “a plain-English mirror of Exhibit B, provided as guidance only. ## 18. Exhibits (binding) Full text of Exhibits A–G appears below: * Exhibit A — License Scope & Delivery * Exhibit B — Technical & Uptime Requirements * Exhibit C — Emissions & Rewards Mechanics * Exhibit D — Transfer & Secondary Policy * Exhibit E — Risk Disclosures * Exhibit F — Referral & Promotions Terms * Exhibit G — Hosting & Delegation Policy ### 18. Order of precedence If there is a conflict: this Agreement controls over the Exhibits; the Exhibits control over the Node Sale TOS; and the TOS controls over site policies. Specific campaign rules control their promotion, except where unlawful. ## 19. modifications Autheo may update incorporated policies prospectively. Material changes to this Agreement or Exhibits will be posted with a new effective date. Protocol parameters and distribution mechanics may be modified prospectively by governance to preserve security and sustainability. Previously accrued amounts are unaffected. ## 20. Term; Suspension; Termination Autheo may suspend or terminate use rights for material breach, unlawful use, or to address emergent threats to network integrity, after notice and a reasonable opportunity to cure where practicable. ## 21. Dispute resolution; Governing law Wyoming law governs (conflict rules excluded). Disputes are subject to binding arbitration under JAMS Streamlined Rules, seated in Wyoming, unless you opt out in writing within 30 days of first use. Class actions and class arbitration are waived to the fullest extent permitted by law. Non-arbitrable claims must be brought in the state or federal courts in Wyoming. ## 22. Notices Autheo legal notices: [legal@autheo.com](mailto:legal@autheo.com) and 30 N Gould St Ste R, Sheridan, WY 82801. Notices to you may be provided via the Sale Site interface or your account email. ## 23. Miscellaneous Assignment subject to Exhibit D; severability; force majeure; no waiver by delay; entire agreement (this Agreement + Exhibits + docs in §16); electronic signatures and counterparts permitted. # THEO token information Source: https://legal.autheo.com/token-information/theo-token-information *Version 1.0. Effective August 6, 2026.* Contact: [legal@autheo.com](mailto:legal@autheo.com) • [https://www.autheo.com/token-launch](https://www.autheo.com/token-launch) ## Purpose This page describes THEO, the native utility token of the Autheo network, including what it is, how it is distributed, how liquidity for it is arranged, and the risks associated with acquiring or holding it. It is a plain-language reference and is not a substitute for the Terms of Service, the General Disclaimer, or any purchase or license agreement that governs a specific transaction. ## What THEO is THEO is the native utility token used to secure and operate the Autheo network. It is designed to be consumed for: * **Staking**: validators stake or bond THEO to participate in block production and earn protocol rewards. * **Transaction fees**: THEO is used to pay network transaction fees. Both of the uses above are live on Autheo mainnet today. THEO is also designed to be used for compute, storage, and AI inference workloads as those layers roll out on mainnet over the coming months; those utilities are not yet operational as of the effective date of this page. ## What THEO is not * THEO is **not a stablecoin**. Its value is not pegged to or backed by any fiat currency, reserve, or basket of assets, and it is not issued under, and does not seek to rely on, any payment-stablecoin licensing framework. * THEO is **not a governance token**. Holding or staking THEO does not confer voting rights over protocol parameters, treasury decisions, or Autheo's corporate governance. * THEO is **not, and is not intended to be, a security** under applicable law. Nothing on this page or elsewhere on autheo.com is investment advice, and nothing should be read as an offer or solicitation to buy or sell THEO in any jurisdiction where such an offer or solicitation would be unlawful. ## Issuing entity and jurisdiction THEO is issued by **THEO TOKENS LTD**, a company organized in the British Virgin Islands. References to "Autheo," "we," or "us" on this page mean THEO TOKENS LTD unless context indicates otherwise. Autheo LLC and the Autheo Foundation are separate legal entities that support different parts of the Autheo ecosystem; THEO TOKENS LTD is the entity responsible for the matters described on this page. Autheo is not currently aware of a jurisdiction-specific restriction preventing US persons from acquiring or holding THEO. This is not a legal opinion, is not exhaustive, and may change. If you are located in, or a resident, national, or entity of, any jurisdiction, you are responsible for determining whether local law restricts your ability to acquire, hold, or transact in THEO, and you should seek independent legal advice before doing so. ## Tokenomics summary * **Total supply**: 7 billion THEO. * **Validator allocation**: 7.5% of total supply (approximately 525 million THEO) is allocated to validator rewards, distributed on a 7-year linear emission schedule. * **Validator set size**: 399 total validator positions across Core, Prime, and Sovereign tiers. * **Illustrative yield**: a Sovereign-tier validator earns approximately 187,969 THEO per year under the current emission schedule. Actual rewards vary with network conditions, validator performance, and the number of active validators, and are not guaranteed. For the full breakdown of tiers, pricing, and emission mechanics, see the [tokenomics documentation](https://www.autheo.com/theo-token) and the [node sale pages](https://www.autheo.com/nodesale). ## Market liquidity arrangement Autheo has engaged **Enflux**, a market-making-as-a-service firm, to act as market maker for THEO. Under this arrangement, Autheo supplies liquidity to Enflux, and Enflux is responsible for managing that liquidity across trading venues, including decentralized exchanges such as Hydrex, on Autheo's behalf. This means Autheo itself does not directly operate a self-serve liquidity pool for THEO. Liquidity provisioning, rebalancing, and related market-making activity are carried out by Enflux under the terms of its engagement with Autheo. Additional detail on the mechanics of this arrangement is available in Autheo's blog coverage of the Enflux engagement, linked from the [token launch page](https://www.autheo.com/token-launch). Market-making activity does not guarantee price stability, a minimum level of liquidity, or any particular trading outcome, and THEO's market price may still be volatile. ## Regulatory context The US regulatory framework for digital assets is still developing, and this section describes the state of that framework as of the effective date above; it will be revised as the framework changes. * The **GENIUS Act** (the Guiding and Establishing National Innovation for U.S. Stablecoins Act, Public Law 119-27) was signed into law on July 18, 2025. It establishes a federal licensing and reserve framework for **payment stablecoins**. Because THEO is not a stablecoin, THEO is not issued under, and does not rely on, the GENIUS Act's licensing framework. * The **CLARITY Act** (the Digital Asset Market Clarity Act), which would establish a broader market-structure framework for digital commodities, has not been enacted. As of the effective date above, it remains under consideration in the US Senate and has not passed the Senate, been reconciled with related legislation, or been signed into law. Autheo is monitoring this legislation and will update this page if it is enacted and applicable to THEO. * No statement on this page should be read as a representation that any specific regulator has classified THEO, or that THEO's status under any enacted or proposed law has been finally determined. Classification determinations of this kind are ultimately made by regulators, courts, or applicable statute, not by Autheo. ## Risk factors Acquiring or holding THEO involves risk. This list is illustrative, not exhaustive. * **Price and market risk.** THEO's market price may be highly volatile and may decline substantially. No return, yield, or price outcome is promised. * **Liquidity risk.** Trading liquidity for THEO depends in part on market-making arrangements described above and on general market conditions. Liquidity may be limited or may decrease at any time. * **Regulatory risk.** Laws and regulations applicable to digital assets, including THEO, are evolving, as described in the Regulatory context section above. Future legislation, rulemaking, or enforcement action could affect THEO's classification, availability, or the manner in which it may be acquired, held, or transferred. * **Protocol and technology risk.** THEO's utility depends on the Autheo network's software and infrastructure, which may contain defects, may be subject to upgrades, and may be affected by network, security, or operational incidents. * **Rollout risk.** Some THEO utilities described on this page (compute, storage, and AI inference) are not yet live and are subject to change, delay, or modification before they become operational. * **Third-party risk.** Arrangements with third parties, including Enflux and any trading venues where THEO is listed, are subject to those parties' own terms, performance, and operational risk, which Autheo does not control. ## No advice; independent assessment Autheo does not provide investment, legal, or tax advice, and does not act as a fiduciary with respect to THEO. Nothing on this page is a recommendation to acquire, hold, or dispose of THEO. You should conduct your own due diligence and consult independent professional advisors before making any decision involving THEO. ## Where this information also appears This page is intended to be linked from, and read alongside: * The [THEO token launch page](https://www.autheo.com/token-launch) * The [THEO tokenomics page](https://www.autheo.com/theo-token) * Autheo's whitepaper, once published * Any page through which THEO can be acquired or accessed ## Contact and updates For questions about this page, contact [legal@autheo.com](mailto:legal@autheo.com). General inquiries can be directed to [info@autheo.com](mailto:info@autheo.com). Autheo may update this page to reflect new information, regulatory developments, or changes to the arrangements described above; the effective date above will be updated when that happens.