BUNIN

Data Sale & Licensing Agreement

Document version: 1.2 · Effective date: 2026-08-01

ENRUES

On-chain binding. The canonical reference to this Agreement is the keccak256 hash of this exact published text at this fixed version (the termsHash). The Buyer accepts by including termsHash when escrowing payment in the DataMarketplaceEscrow contract. The Seller accepts by signing and submitting the EIP-712 ConsentDelivery message that commits to the same termsHash.

Operator / platform: BUNIN, provided and operated from Spain by Konstantin Bunin (N.I.E. Y2703732G), calle Felipe Menendez, 11, 3A, 33206, Gijon, Asturias, Spain - contact: support@thebunin.app. BUNIN operates the marketplace software and acts as initial technical Arbiter. BUNIN is not a party to the data sale itself.

1. Parties, age, capacity, and definitions

Seller / Data Owner is the natural person who owns or controls the personal and/or medical data offered for sale and who is the data subject under the GDPR. Buyer is the person or legal entity that escrows payment to purchase a limited license. Requested scope is the precise purpose, data category, permitted analysis, territory, retention period, recipient type, and restrictions declared by the Buyer and accepted by the Seller. Both parties must be at least 18 and legally capable.

2. Legal and regulatory framing

The transaction may involve health, genetic, or other special-category personal data under Article 9 GDPR. The Seller's consent must be explicit, specific, informed, and transaction-specific. The Buyer must maintain its own Article 6 legal basis and Article 9 condition where applicable.

BUNIN never writes medical content on-chain. On-chain records contain wallet addresses, hashes, signatures, timing, and settlement metadata, which may still be personal or pseudonymous data where a person can be identified.

3. Requested scope (mandatory transaction terms)

Each purchase request must define its Requested scope. If the scope is missing, ambiguous, or overbroad, the Seller should not deliver data until clarified.

Before delivery, the Buyer must provide a compliance declaration sufficient for the Seller to assess lawfulness for the specific request, including at minimum: (a) identified Article 6 legal basis; (b) identified Article 9 condition where special-category data is involved; (c) transfer mechanism where non-EEA access/transfer is planned; and (d) confirmation whether a DPIA is required and has been completed where legally required. If this declaration is missing, materially incomplete, or inconsistent with the Requested scope, the Seller may refuse delivery without breach.

4. Rights granted

The Seller does not transfer ownership or waive personal rights. The Buyer receives a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to process the specific Data only within the Requested scope.

5. GDPR roles and buyer obligations

The Buyer acts as an independent controller for post-delivery processing and must comply with GDPR, ePrivacy rules where relevant, Spanish and EU law, applicable international transfer rules, and any mandatory local law. The Buyer must implement data protection by design and by default, security controls, Article 28 processor terms, records of processing, DPIA where required, and valid international transfer mechanisms.

The Buyer further represents that all pre-delivery compliance declarations provided under Section 3 are accurate and complete in all material respects at the time of delivery.

6. Prohibited uses

The Buyer must not re-identify a data subject, resell or disclose the Data, use it for insurance, credit, employment, housing, healthcare access, law-enforcement, immigration, discrimination, unlawful profiling, significant automated decisions, or AI/model use unless expressly authorized in the Requested scope and lawful.

7. Retention, deletion, and data-subject rights

The Buyer may retain Data only for the scope's retention period. On expiry, valid withdrawal, erasure request, or license termination, the Buyer must delete Data, keys, working copies, derived identifiable or pseudonymous records, and processor copies within 30 days unless strictly required by law. The Seller retains GDPR rights, including withdrawal, erasure, complaint, and judicial remedy.

8. International transfers

Transfers or remote access outside the EEA require a valid GDPR Chapter V mechanism, such as adequacy decision or Standard Contractual Clauses, plus transfer impact assessment and supplementary measures where required.

9. Blockchain and escrow terms

The Buyer escrows the price in DataMarketplaceEscrow. The Seller encrypts the Data, uploads or makes available the encrypted payload, wraps the decryption key to the Buyer's public key, and records dataCommitment and keyDeliveryCommitment through the consent-delivery flow. The dispute window is 3 days unless the contract is upgraded or the request states a different valid period.

If the Buyer confirms delivery, or if the window expires without dispute, payment is released or becomes claimable. The Arbiter decides only the narrow technical question of valid key delivery for the committed encrypted Data; it does not adjudicate later misuse or GDPR compliance.

To mitigate conflicts of interest, the Arbiter should document the technical basis for each decision and preserve relevant technical evidence. Where either party challenges impartiality, the parties should use a mutually agreed independent expert or arbitration forum for review of the technical determination, without prejudice to mandatory rights before courts or supervisory authorities.

9A. Taxes and reporting

Each party is solely responsible for its own tax, reporting, withholding, and accounting obligations arising from transactions under this Agreement, except where mandatory law requires otherwise.

10. Liability, remedies, and enforcement

The Buyer's Requested-scope, security, deletion, transfer, and non-misuse duties are material terms. Breach may entitle the Seller to injunctive relief, deletion, damages, statutory remedies, and compensation under Article 82 GDPR where applicable. The Seller is an intended third-party beneficiary and may enforce the Buyer's obligations directly.

BUNIN is not a party to the sale and is not liable for the Buyer's downstream processing. BUNIN's liability is limited to operating the software and initial technical Arbiter role in good faith, to the maximum extent permitted by law.

11. Governing law and jurisdiction

This Agreement is governed by Spanish law and applicable European Union law, including the GDPR. Without prejudice to mandatory consumer, data-subject, weaker-party, or local-language rights and protections that allow proceedings elsewhere or require additional safeguards, the parties submit to the courts of Gijon, Asturias, Spain. Nothing limits GDPR Articles 77-79 rights.

12. Annex - minimum Requested scope template

Purpose: [specific purpose]
Data categories requested: [specific categories]
Permitted outputs: [internal analysis / aggregate non-identifiable result / other]
AI/model use: [not permitted unless expressly stated]
Retention period: [maximum period, default 12 months]
Processing territory: [EEA only / third-country transfer with mechanism]
Recipients/processors: [named categories]
Security controls: [encryption, access controls, deletion evidence]
Special restrictions: [if any]