IQDESK ENTERPRISE — END-USER LICENSE AGREEMENT AND TERMS OF SERVICE
Version 2.0 — Effective 20 August 2026

PLEASE READ THESE TERMS CAREFULLY BEFORE INSTALLING OR USING IQDESK ENTERPRISE. BY CLICKING
"I ACCEPT", CHECKING THE ACCEPTANCE BOX, OR INSTALLING, DEPLOYING, OR USING THE SOFTWARE, YOU
("CUSTOMER") AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE, DO NOT INSTALL OR USE THE
SOFTWARE.

1. THE AGREEMENT
   This is a legal agreement between Customer and NurIQ Technologies ("NurIQ", "we", "us",
   or "our") governing use of the IQDesk Enterprise IT Service Management and Remote Monitoring
   and Management software, including its server components, web application, Windows agent,
   installers, and all associated documentation (collectively, the "Software").

2. LICENSE GRANT
   Subject to Customer's compliance with these Terms, NurIQ grants Customer a limited,
   non-exclusive, non-transferable, revocable license to install and use the Software solely
   for Customer's own internal business operations. Customer may not resell, sublicense,
   reverse-engineer, or redistribute the Software except as expressly permitted in writing by
   NurIQ.

3. DISCLAIMER OF WARRANTIES
   THE SOFTWARE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS
   FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. NurIQ DOES NOT WARRANT THAT THE
   SOFTWARE WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF HARMFUL COMPONENTS, OR THAT ANY
   DEFECTS WILL BE CORRECTED.

4. LIMITATION OF LIABILITY
   TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER NurIQ TECHNOLOGIES LLP NOR ITS
   OWNERS, DIRECTORS, EMPLOYEES, OR CONTRACTORS (INCLUDING ITS FOUNDER, FAIZ) SHALL BE LIABLE
   FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES,
   INCLUDING BUT NOT LIMITED TO LOSS OF DATA, LOSS OF PROFITS, LOSS OF BUSINESS, BUSINESS
   INTERRUPTION, OR THE COST OF SUBSTITUTE SERVICES, ARISING OUT OF OR RELATED TO THE
   INSTALLATION, DEPLOYMENT, CONFIGURATION, OR USE OF (OR INABILITY TO USE) THE SOFTWARE, EVEN
   IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THIS INCLUDES, WITHOUT LIMITATION, DAMAGE OR
   LOSS ARISING FROM: MISCONFIGURATION BY CUSTOMER OR ITS PERSONNEL; FAILURE OF THIRD-PARTY
   INFRASTRUCTURE (NETWORKS, CLOUD PROVIDERS, OPERATING SYSTEMS, DATABASES) THE SOFTWARE RUNS
   ON OR INTERACTS WITH; ACTIONS TAKEN BY CUSTOMER'S OWN ADMINISTRATORS USING THE SOFTWARE'S
   REMOTE ACCESS, REMOTE CONTROL, OR AUTOMATION FEATURES; OR CUSTOMER'S FAILURE TO MAINTAIN
   ITS OWN BACKUPS, ACCESS CONTROLS, OR SECURITY PRACTICES. NurIQ's TOTAL AGGREGATE LIABILITY
   ARISING OUT OF THESE TERMS SHALL NOT EXCEED THE AMOUNT, IF ANY, PAID BY CUSTOMER FOR THE
   SOFTWARE IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.

5. CUSTOMER RESPONSIBILITIES
   Customer is solely responsible for: (a) lawful use of the Software, including compliance
   with all data protection, labor, and monitoring-disclosure laws applicable to Customer's use
   of remote monitoring, remote control, and endpoint inventory features; (b) maintaining its
   own backups independent of any backup feature the Software provides; (c) securing the
   credentials, certificates, and infrastructure Customer controls; and (d) obtaining any
   consents required from its own end users or employees before deploying monitoring or remote
   access agents to their devices.

6. DATA PROTECTION (GDPR, UAE, GCC, AND INDIA-ALIGNED TERMS)
   Where Customer's use of the Software involves personal data subject to the EU/UK General
   Data Protection Regulation ("GDPR"), the United Arab Emirates Personal Data Protection Law
   (Federal Decree-Law No. 45 of 2021), the personal data protection law of any other GCC
   member state (including Saudi Arabia's Personal Data Protection Law, Qatar's Law No. 13 of
   2016, Bahrain's Personal Data Protection Law, and Oman's Personal Data Protection Law), or
   India's Digital Personal Data Protection Act, 2023 ("DPDPA") (each, a "Data Protection Law"),
   the following applies, regardless of which Data Protection Law governs the personal data in
   question:
   a. Roles. As between the parties, Customer is the data controller (or, under the DPDPA, the
      "Data Fiduciary") for personal data processed through the Software (e.g., end-user names,
      device identifiers, ticket contents, audit logs). NurIQ acts, where applicable, as a data
      processor (or "Data Processor" under the DPDPA) solely for optional features that transmit
      data to NurIQ-operated infrastructure (e.g., managed cloud backup destinations); for a
      self-hosted or Customer's own Docker/Compose, on-premises, or private-cloud deployment,
      NurIQ has no access to Customer's data at all.
   b. Data minimization and security. The Software is designed to keep personal data within
      Customer's own infrastructure by default, encrypts secrets and backups at rest, supports
      role-based access control, multi-factor authentication, and maintains immutable audit
      logs of data access — Customer remains responsible for configuring these controls
      appropriately for its own regulatory obligations.
   c. Data subject rights. Customer is responsible for responding to data subject/data
      principal access, rectification, erasure, and portability requests using the Software's
      existing administrative tools (user management, ticket/asset export, audit log).
   d. Breach notification. If NurIQ becomes aware of a security incident affecting Customer
      data processed under this section, NurIQ will notify Customer without undue delay so
      Customer can meet its own regulatory notification obligations. This notification
      commitment does not, by itself, make NurIQ responsible or liable for the underlying
      incident — see Section 7.
   e. Sub-processors. NurIQ will not engage sub-processors for Customer data without providing
      Customer reasonable notice.
   f. Precedence. Where two or more Data Protection Laws apply to the same personal data and
      impose conflicting obligations, Customer is responsible for determining which obligation
      takes precedence for its own compliance purposes; the Software's controls in (b) are
      common to all of the Data Protection Laws listed above and are not tailored to any single
      one.

7. SECURITY INCIDENTS AND VULNERABILITY RESPONSE
   a. Vulnerability remediation commitment. NurIQ uses industry-standard security practices in
      developing the Software (including encryption in transit and at rest, role-based access
      control, multi-factor authentication, TLS certificate pinning for agent communications,
      and immutable audit logging) and accepts vulnerability reports from Customer or from
      independent researchers. Where NurIQ confirms a reported issue is a genuine vulnerability
      in the Software, NurIQ will investigate and remediate it within a reasonable time,
      consistent with its severity, and will make a fixed version available to Customer.
   b. No liability for security incidents. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW,
      NurIQ IS NOT RESPONSIBLE OR LIABLE FOR ANY UNAUTHORIZED ACCESS, DATA BREACH, CYBERATTACK,
      MALWARE OR RANSOMWARE INFECTION, OR OTHER SECURITY INCIDENT AFFECTING CUSTOMER'S
      DEPLOYMENT, DATA, OR INFRASTRUCTURE — INCLUDING ONE ENABLED, IN WHOLE OR IN PART, BY A
      VULNERABILITY IN THE SOFTWARE ITSELF — EXCEPT TO THE EXTENT THE INCIDENT IS DIRECTLY
      CAUSED BY NurIQ's GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. Customer's sole and exclusive
      remedy for a vulnerability in the Software is NurIQ's remediation commitment in
      paragraph (a); it is not a right to damages, refund, or other compensation, except as
      already provided for in Section 4.
   c. Relationship to Section 4. This Section does not expand NurIQ's liability beyond, and
      operates within, the limitation of liability and liability cap set out in Section 4.
   d. Interaction with Sections 5 and 6. This Section does not reduce Customer's own
      responsibilities under Sections 5 (Customer Responsibilities) and 6 (Data Protection);
      a security incident caused by Customer's own misconfiguration, credential handling, or
      failure to apply a NurIQ-provided fix remains Customer's responsibility under those
      Sections.

8. HEALTHCARE DATA (ADHICS-ALIGNED TERMS)
   Where Customer operates in, or provides services to, the healthcare sector in the United
   Arab Emirates and is subject to the Abu Dhabi Healthcare Information and Cyber Security
   Standard ("ADHICS") or equivalent regional healthcare information security standards:
   a. The Software provides technical controls that support ADHICS-aligned operation, including
      encryption of data at rest and in transit, role-based access control, mandatory and
      optional multi-factor authentication, immutable audit logging of access to tickets,
      assets, and remote sessions, and configurable session/idle timeouts.
   b. Customer remains solely responsible for classifying its own data (including any asset
      records tagged as medical devices), for its own risk assessments, and for satisfying its
      own obligations as a regulated healthcare entity or service provider to one. Use of the
      Software's technical controls does not by itself constitute ADHICS certification or
      compliance, which remains Customer's responsibility to obtain and maintain.
   c. Customer must ensure any remote monitoring or remote control of medical devices through
      the Software is authorized under its own change-management and clinical-safety policies
      before enabling it.

9. INDEMNIFICATION
   Customer agrees to indemnify and hold harmless NurIQ Technologies, its owners, and
   personnel from any third-party claim arising out of Customer's use of the Software in
   violation of these Terms or applicable law, including claims brought by Customer's own
   employees or end users regarding monitoring or remote access performed through the Software.

10. TERM AND TERMINATION
    These Terms remain in effect for as long as Customer uses the Software. NurIQ may suspend or
    terminate Customer's license for material breach of these Terms. Upon termination, Customer
    must cease use of the Software; Sections 3, 4, 6, 7, 8, 9, and 11 survive termination.

11. GOVERNING LAW
    These Terms are governed by the laws of the United Arab Emirates, without regard to its
    conflict-of-laws principles, and any dispute shall be subject to the exclusive jurisdiction
    of the competent courts of the United Arab Emirates, without prejudice to any mandatory
    consumer or data-protection rights Customer may have under its own local law. Nothing in
    this Section limits any mandatory, non-waivable statutory right Customer may have under the
    law of the GCC member state or of India in which Customer is domiciled, to the extent such
    right cannot lawfully be excluded by contract.

12. ENTIRE AGREEMENT
    These Terms constitute the entire agreement between Customer and NurIQ regarding the
    Software and supersede any prior agreements or representations, written or oral, concerning
    its subject matter. If any separately signed order form or master services agreement exists
    between Customer and NurIQ, its terms take precedence over these Terms to the extent of any
    conflict.

13. CONTACT
    Questions about these Terms may be directed to NurIQ Technologies at
    info@nuriqtechnologies.uk.

© 2026 NurIQ Technologies. All rights reserved.
