Service Agreement · April 2026

Viska Völundr Engagement

AI agent system development services for Viska Macro fund research
Service ProviderBoas [Surname] · Galdr ehf. (in formation)
ClientViska sjóðir ehf., kt. 471221-0900
Effective DateTarget: 1 May 2026
Initial TermThree (3) calendar months
Service
Provider
Boas [Surname], an individual resident in the Federal Republic of Germany, acting as a sole-trader / Freiberufler service provider in the field of software development, with intent to assign this Agreement to Galdr ehf. (an Icelandic einkahlutafélag in formation as of the Effective Date) upon issuance of its registration number ("kennitala") by the Icelandic Companies Registry, in accordance with Section 18 below.
Client
Viska sjóðir ehf., kennitala 471221-0900, an Icelandic fund management company having its registered office at [address], Reykjavík, Iceland.
Reference
Each a "Party" and together the "Parties".
Section 1

Recitals

WHEREAS Service Provider has previously developed for Client an AI-driven research system known as "Mímir" which is now operated by Client;

WHEREAS Client wishes to engage Service Provider to design, develop, and progressively iterate on a separate, dedicated AI agent system to support Client's daily research operation for its Viska Macro fund (the "Project");

WHEREAS the Project is intended to evolve over time on the basis of an indicative roadmap, with priorities reviewed monthly, rather than against fixed deliverable dates;

WHEREAS Service Provider is in the process of incorporating Galdr ehf. and intends to assign this Agreement to that entity upon its formation;

NOW, THEREFORE, the Parties agree as follows.

Section 2

Definitions

In this Agreement, unless the context otherwise requires:

"Agreement"
means this service agreement, including all Schedules, as amended from time to time.
"Background IP"
means intellectual property owned, developed, or licensed by a Party prior to or independently of this Agreement.
"Client Database"
means the dedicated database (or databases) instantiated for the Project containing Client-specific data, schemas, run logs, and operational records.
"Client Deliverables"
means the configurations, code, prompts, schemas, integrations, and documentation specifically created for Client under this Agreement, as further described in Schedule E.
"Client-Provided Resources"
has the meaning set out in Section 6.4.
"Confidential Information"
has the meaning set out in Section 8.
"Effective Date"
means [DATE] (target: 1 May 2026 or such other date as the Parties confirm in writing).
"Handover Deliverables"
means the items specified in Schedule E.
"Indicative Maintenance Stack"
means the tech stack described in Schedule F.
"Maintenance Fee"
has the meaning set out in Section 16.2.
"Maintenance Services"
has the meaning set out in Section 16.1.
"Pantheon"
means Service Provider's internal development environment, framework, agents, and tooling, used by Service Provider to design, build, and test client systems. Pantheon is Service Provider's Background IP and is expressly excluded from the Client Deliverables.
"Project Repositories"
means the source-code repositories created specifically for the Project.
"Roadmap"
means the document attached as Schedule A, as amended in writing from time to time per Section 3.3.
"Service Fee"
has the meaning set out in Section 5.1.
"System"
means the AI agent system, including its agents, workflows, user interface, database, configurations, and runtime infrastructure, designed and developed for Client under this Agreement, excluding Pantheon and any other Service Provider Background IP.
"VAT"
means value-added tax, including Icelandic virðisaukaskattur (VSK) and German Umsatzsteuer (USt) as applicable.
Section 3

Services

3.1Engagement

Service Provider shall provide AI agent system development services to Client for Client's Viska Macro fund research operation, in accordance with the Roadmap and this Agreement.

3.2Standard of Performance

Service Provider shall perform the services with the degree of skill, care, and diligence reasonably expected of a qualified professional in the field of AI software development. Service Provider does not guarantee any specific outcome, performance metric, profit, return, system uptime, or completion date.

3.3Roadmap

The Roadmap describes the Parties' shared objectives and indicative timeline as of the Effective Date. The Roadmap is directional, not contractual. The Parties may amend the Roadmap by written agreement (email confirmation by both Parties is sufficient) at any time, and any such amendment supersedes the corresponding portions of the Roadmap on a going-forward basis.

3.4Monthly Review

The Parties shall meet on or about the first business day of each calendar month to review progress against the Roadmap, discuss adjustments, and document priorities for the upcoming month. Documented outcomes of the monthly review are deemed Roadmap amendments per Section 3.3 to the extent consistent in form.

3.5No Acceptance Gate

The Parties acknowledge that the Project is iterative and that no deliverable is conditioned upon Client's formal acceptance. Client's sole remedy for dissatisfaction with the work is termination per Section 4.3.

3.6Best-Efforts; No Warranty of Outcome

Service Provider's obligation is to perform services on a best-efforts basis. Service Provider does not warrant that any particular feature will function as initially conceived, that any particular date will be met, or that any particular benefit will be realized.

Section 4

Term and Termination

4.1Effective Date

This Agreement commences on the Effective Date.

4.2Initial Term

The initial term is three (3) calendar months from the Effective Date (the "Initial Term"). Following the Initial Term, this Agreement continues on a month-to-month basis until terminated in accordance with this Section 4.

4.3Termination for Convenience

Either Party may terminate this Agreement at any time, including during the Initial Term, by providing thirty (30) days' written notice to the other Party. No cause is required.

4.4Termination for Cause

Either Party may terminate this Agreement immediately upon written notice if the other Party (a) materially breaches this Agreement and fails to cure within fourteen (14) days of written notice describing the breach, or (b) becomes insolvent, files for bankruptcy, or ceases regular business operations.

4.5Effect of Termination

Upon termination or expiration of this Agreement for any reason:

  1. Service Provider shall issue a final invoice prorated to the termination date, payable per Section 5.2.
  2. Within fourteen (14) days after the termination date, Service Provider shall transfer the Handover Deliverables to Client per Schedule E and Section 7.
  3. Service Provider shall revoke its access to the Client-Provided Resources and any Client-controlled systems within five (5) business days after the handover is complete, or immediately upon Client's request, whichever is earlier.
  4. Each Party shall return or destroy the other Party's Confidential Information per Section 8, except (i) one archival copy may be retained for legal, audit, or backup-recovery purposes only, and (ii) Service Provider may retain Client Deliverables to the extent reasonably necessary to perform Maintenance Services if elected by Client per Section 16.
  5. The following Sections survive termination: 7 (Intellectual Property), 8 (Confidentiality), 9 (Data Protection), 10 (Security), 11 (Backups and Audit), 13 (Liability), 14 (Indemnification), 15 (Compliance), 16 (Post-Termination Maintenance Option), 18 (Assignment), 20 (Governing Law and Disputes), 21 (General Provisions), and this Section 4.5.

4.6Handover Cooperation

Both Parties shall cooperate in good faith to effect the handover. Service Provider shall provide up to eight (8) hours of synchronous knowledge-transfer assistance at no additional charge. Further assistance is billable at Service Provider's then-current hourly rate. Client shall procure its own infrastructure (Git hosting, database hosting, credentials, third-party platform accounts) sufficient to receive the Handover Deliverables prior to the handover date.

Section 5

Fees and Payment

5.1Service Fee

Client shall pay Service Provider a monthly fee of ISK 1,200,000 (one million two hundred thousand Icelandic krónur) plus applicable VAT (the "Service Fee"). The Service Fee covers Service Provider's professional services and all infrastructure, tooling, hosting, third-party software, and operational costs incurred by Service Provider in performing the services, except as set out in Section 6.4 (Client-Provided Resources) and Section 16.4 (Client-Procured Components).

5.2Invoicing

Service Provider shall issue an invoice on or about the first business day of each calendar month for that month's services. Invoices are payable within fourteen (14) days of the invoice date. Late payments accrue interest at the rate set out in Icelandic Act no. 38/2001 on Interest and Price Indexation.

5.3Currency

Invoices are denominated in ISK. VAT treatment is per Section 5.4.

5.4VAT Treatment During Bridge Period

As of the Effective Date, Service Provider operates as a German-resident sole-trader / Freiberufler. The Parties acknowledge that, during this bridge period and prior to the assignment to Galdr ehf. per Section 18, the supply of services from a German-established service provider to an Icelandic-established business customer falls outside the scope of German VAT under §3a paragraph 2 of the German Value Added Tax Act (UStG), with VAT accounted for in Iceland by the recipient under the reverse-charge mechanism in accordance with Icelandic VAT law. Service Provider shall accordingly issue invoices without German VAT and with a reverse-charge notation, and Client shall account for any applicable Icelandic VAT.

Upon assignment to Galdr ehf. per Section 18, invoices shall thereafter be issued by Galdr ehf. as a domestic Icelandic supplier to a domestic Icelandic recipient, with Icelandic VSK at the prevailing rate (currently 24%) added to invoiced amounts.

Tax-advisor review required

The Parties shall cooperate on reasonable invoice-format adjustments needed for VAT compliance. Treatment in this Section 5.4 is subject to confirmation by qualified tax advisors and shall be modified by written amendment if such confirmation requires a different approach.

5.5No Set-Off

Client shall pay all invoiced amounts in full without set-off, counterclaim, or deduction, except as required by applicable law.

Section 6

Client-Provided Resources

6.1Resources Required

Client shall procure, maintain, and bear all costs of the Client-Provided Resources specified in Schedule C, which are required for Service Provider's performance of the services.

6.2Access Grant

Client grants Service Provider access to the Client-Provided Resources for the duration of this Agreement. Service Provider shall use such access solely for performance of this Agreement and shall not use the Client-Provided Resources for any other purpose.

6.3Administrative Ownership

Client retains administrative ownership of the Client-Provided Resources. Service Provider shall not transfer, share, or expose access credentials for Client-Provided Resources to any third party.

6.4Usage Monitoring

Service Provider shall monitor Service Provider's use of Client-Provided Resources and shall promptly notify Client if usage trends unexpectedly toward limits or budget thresholds.

6.5Liability for Usage Costs

Client bears all usage costs for Client-Provided Resources arising from operation of the System within reasonable parameters. Service Provider is liable for usage costs caused by Service Provider's gross negligence or willful misconduct, subject to the cap in Section 13.3.

6.6Risk of Insufficient Capacity

Client bears the risk of insufficient capacity, rate-limit exhaustion, or service interruption attributable to the Client-Provided Resources or to the Client-Procured Components in Schedule F.2.

6.7Inference Provider Resilience

The System is designed to switch between language-model inference providers (for example via OpenRouter or equivalent abstraction) such that an outage at any single inference provider does not, in itself, cause a System-wide outage. Service Provider's commitment in this Section is best-efforts; Service Provider is not liable for cascading failures across multiple inference providers, for outages of the OpenRouter-equivalent abstraction itself, or for failures attributable to Client-Provided Resources.

Section 7

Intellectual Property

7.1Background IP

Each Party retains all rights in its Background IP. Service Provider's Background IP includes (without limitation) Pantheon, generic agent patterns, reusable skills, development tooling, and Service Provider's open-source contributions. Client's Background IP includes (without limitation) Client's fund data, the Mímir corpus, the Viska Screener framework, Client's brand assets, and Client's pre-existing systems.

7.2Client Deliverables

Subject to Section 7.3 and Client's payment in full of invoiced fees, Service Provider assigns to Client all rights in the Client Deliverables. Client owns all data the System processes for Client.

7.3Service Provider Retained Rights

Service Provider retains:

  1. all Background IP, including the Pantheon development framework. For the avoidance of doubt, Pantheon is Service Provider's internal development environment and forms no part of the Client Deliverables. No Pantheon code, agent definitions, framework artifacts, shared infrastructure references, or constellation-named components shall be present in the Client Deliverables.
  2. all general knowledge, methodologies, design techniques, architectural patterns, and non-Client-specific learnings gained during the engagement, which Service Provider may apply to other engagements and to the evolution of Service Provider's own products;
  3. ownership of any third-party open-source components incorporated into the System, including without limitation Mastra, n8n, and standard web framework dependencies, which retain their respective licenses.

7.4Composition of the System

The System delivered under this Agreement consists solely of (i) configurations and code authored specifically for the Project, (ii) third-party open-source and licensed components used as runtime dependencies, and (iii) Project-specific data, schemas, and operational records. The System does not contain any portion of Pantheon, Service Provider's internal tooling, or shared infrastructure used across Service Provider's other engagements.

7.5Mímir and Viska Screener

The Mímir corpus and the Viska Screener framework are Client's Background IP. Service Provider's access during the Project is read-only for integration purposes only.

7.6Repository Ownership During Term

The Project Repositories are hosted by Service Provider during the Term on infrastructure controlled by Service Provider. The Project Repositories are isolated from Pantheon and from other Service Provider clients' code at the repository level. Client receives read access to the Project Repositories upon request during the Term.

7.7Repository Transfer at Termination

Upon termination, Service Provider shall transfer ownership of the Project Repositories to Client by either (i) initiating a repository transfer to Client's hosting account on the same platform, or (ii) providing Client with a complete Git bundle of the repositories for Client's import into Client-controlled hosting. Method is at Service Provider's discretion unless the Parties agree otherwise.

7.8Database Transfer at Termination

Service Provider shall provide Client with a complete snapshot of the Client Database in a standard portable format. The Client Database is operated on infrastructure dedicated to the Project, such that the snapshot may be transferred in full without partitioning or redaction.

7.9License-Back to Service Provider

Notwithstanding the assignment in Section 7.2, Client grants Service Provider a perpetual, irrevocable, worldwide, non-exclusive, royalty-free license to use the general knowledge, methodologies, and non-Client-specific techniques developed during the Project for the purpose of evolving Service Provider's products and serving other clients. This license does not extend to Client's Confidential Information, Client-specific configurations or code, fund data, trading strategy, the Mímir corpus, the Viska Screener framework, or any artifact identifiable as belonging to Client. Service Provider shall not represent that Client endorses or is associated with any subsequent Service Provider product.

7.10Open-Source Notice

Service Provider shall provide Client with a list of all open-source components used in the Client Deliverables and their respective licenses as part of the Project Documentation under Schedule E. Client's use of such components is governed by their original licenses.

Section 8

Confidentiality

8.1Definition

"Confidential Information" means non-public information disclosed by one Party to the other in connection with this Agreement, including (without limitation) Client's fund positions, NAV history, trading strategy, LP information, client lists, the contents of the Mímir corpus, the Viska Screener framework, and Client's pre-existing systems; and Service Provider's technical architecture, source code, methodologies, pricing, internal tooling, and Pantheon.

8.2Obligations

Each Party shall (a) hold the other's Confidential Information in strict confidence, (b) use it only to perform under this Agreement, (c) limit access to personnel and advisors with a need to know who are bound by confidentiality obligations at least as protective as this Section, and (d) protect it with the same degree of care it uses for its own Confidential Information of similar sensitivity, but no less than reasonable care.

8.3Exclusions

Confidential Information does not include information that (a) is or becomes publicly known through no fault of the receiving Party, (b) was known to the receiving Party prior to disclosure without confidentiality obligation, (c) is rightfully received from a third party without confidentiality obligation, or (d) is independently developed without use of the disclosing Party's Confidential Information.

8.4Compelled Disclosure

The receiving Party may disclose Confidential Information to the extent required by law, regulation, or court order, provided it gives the disclosing Party prompt written notice (where lawful) and cooperates with reasonable efforts to limit the scope of disclosure.

8.5Survival

Confidentiality obligations survive termination of this Agreement for five (5) years, except for trade secrets and Client's investment data, which remain confidential for as long as they retain trade-secret or sensitive-financial status under applicable law.

Section 9

Data Protection

9.1Compliance

Each Party shall comply with applicable data protection laws, including the Icelandic Act on the Protection of Privacy as regards the Processing of Personal Data and Iceland's implementation of the EU General Data Protection Regulation (GDPR), in performing this Agreement.

9.2Personal Data

The Parties acknowledge that the Project, in its initial scope, primarily processes commercial fund data (positions, NAV, market data, news content, technical-analysis outputs) and is not expected to process material volumes of personal data. To the extent personal data is processed (for example LP names or contact records contained in the Mímir corpus), the Parties shall enter into a Data Processing Agreement (DPA) substantially in the form to be agreed prior to such processing commencing.

9.3Data Residency

Service Provider shall use reasonable efforts to ensure that Client Database storage and processing occur within the European Economic Area (EEA). Cross-border processing outside the EEA, where necessary for service operation, shall be subject to appropriate safeguards (Standard Contractual Clauses or equivalent).

9.4Data Subject Requests

The Parties shall cooperate on a reasonable basis to respond to requests by data subjects exercising rights under applicable data-protection law.

Section 10

Security

10.1Service Provider Security Practices

Service Provider shall implement and maintain reasonable security measures appropriate to the nature of the data processed, in accordance with the security best practices set out in Schedule G. Such measures include (without limitation):

  1. access control: principle of least privilege; named-user authentication for administrative access; multi-factor authentication on all developer and operator accounts;
  2. credential isolation: secrets stored in dedicated secret stores or platform-managed environment variables; secrets never committed to source-code repositories; secrets never logged or printed;
  3. transport security: TLS 1.2 or higher for all client-facing endpoints and inter-service communication;
  4. network controls: client portal and database endpoints protected behind authenticated entry points; database direct-access disabled from public networks; administrative interfaces restricted by IP allowlist or zero-trust gateway where reasonably available;
  5. auditability: append-only operational logs for material system actions, retained for at least the term of this Agreement plus one year, viewable by Client through the client portal per Section 11;
  6. software hygiene: timely application of security patches and dependency updates for the System's components;
  7. personnel: confidentiality obligations on all personnel with access to Client Confidential Information.

10.2Foreign Actor Defense

Service Provider shall implement controls reasonably designed to detect and prevent unauthorized access by external actors, including (without limitation) gateway-level authentication for the client portal, row-level security policies on the Client Database where the underlying platform supports them, rate limiting on public endpoints, and rejection of unauthenticated database connections from public networks.

10.3Incident Notification

Service Provider shall notify Client without undue delay (and in any event within seventy-two (72) hours) after becoming aware of any actual or reasonably suspected security incident materially affecting the Client Database, the System's authentication, or Client's Confidential Information. The notification shall describe the nature of the incident, the data and systems affected, the steps taken to contain it, and proposed remediation.

10.4Client Cooperation

Client shall cooperate in good faith with Service Provider's security measures, including procuring its own access credentials promptly, applying multi-factor authentication on Client-administered systems where available, and notifying Service Provider promptly of suspected compromise of Client's own accounts.

10.5No Warranty of Absolute Security

Service Provider does not warrant that the System or its operations are immune to compromise. Section 10 sets out a standard of reasonable care, not a guarantee of outcome.

Section 11

Backups and Audit

11.1Backups

Service Provider shall configure automated backups of the Client Database and the Project Repositories with the following characteristics:

  1. Frequency: at least daily for the Client Database; on every commit for the Project Repositories.
  2. Destination: backups shall be written to a Client-owned cloud storage location designated in writing by Client (for example a Client-owned Google Drive folder or Client-owned Dropbox folder), in addition to any backups provided natively by the underlying platforms (such as Supabase point-in-time recovery).
  3. Retention: at least thirty (30) days of daily Database backups; full Repository history.
  4. Encryption at rest: backups shall be encrypted at rest using industry-standard encryption.
  5. Restoration: Service Provider shall test restoration from backup at least once per calendar quarter and document the result in the operational log.

11.2Client Access to Backups

Because backups are written to Client-owned storage, Client retains independent access to backup data at all times, including after termination. Service Provider shall not be the sole holder of backup material.

11.3System Audit Visibility

Service Provider shall make operational audit information visible to Client through the client portal interface that forms part of the System. Such information shall include (at minimum):

  1. System health indicators and recent operational status;
  2. Run logs for agent invocations, including timestamp, inputs summary, outputs summary, errors, and duration;
  3. Recent deployment, configuration-change, and dependency-update events;
  4. Notable security events recorded by the System (failed authentication attempts, rate-limit triggers, and similar).

11.4Out-of-Portal Audit Requests

On reasonable written request, Service Provider shall provide further audit information not available through the portal, subject to reasonable scope and a reasonable response window.

Section 12

Disaster Recovery and Resilience

12.1Disaster Scenarios and Mitigations

The Parties acknowledge and accept the disaster scenarios and corresponding mitigation approaches set out in Schedule H. Schedule H reflects the System's design assumptions and is not a service-level commitment unless explicitly stated therein.

12.2Inference Provider Outages

The System is designed to switch between inference providers via OpenRouter or equivalent abstraction, such that an outage at any single inference provider should not, in itself, cause a System-wide outage. Service Provider's commitment in this Section is best-efforts.

12.3Platform Outages

The System depends on third-party platforms (Railway, Supabase, n8n, and others) for which Service Provider is not the operator. In the event of an outage of any such platform, Service Provider shall (a) communicate the outage status to Client through the client portal or other agreed channel, (b) follow the platform vendor's recommended remediation, and (c) where reasonable, switch to a fallback configuration. Service Provider is not liable for the duration or consequences of platform outages outside Service Provider's reasonable control.

12.4Backup-Based Recovery

In the event of catastrophic data loss attributable to the Client Database, Service Provider shall restore from the most recent available backup (per Section 11.1) on a best-efforts basis. Recovery point objective (RPO) is no greater than twenty-four (24) hours under normal operating conditions.

12.5No SLA Beyond This Section

Sections 12.1 through 12.4 are best-efforts commitments. No specific service-level agreement (uptime percentage, response time, recovery time) applies unless separately documented in writing and signed by both Parties.

Section 13

Liability

13.1No Investment Advice; No Fiduciary Relationship

Defensive Clause · Critical

The services and any outputs from the System are informational tools for Client's internal use. Nothing in this Agreement constitutes investment advice, financial advice, regulatory advice, or a recommendation to buy, sell, or hold any security or financial instrument. All investment, trading, and portfolio decisions are made solely by Client and its personnel. Service Provider is not registered or regulated as an investment advisor, broker-dealer, or financial intermediary in any jurisdiction.

No fiduciary, agency, or advisory relationship is created by this Agreement.

13.2Client's Responsibility

Client confirms that it has the expertise, regulatory permissions, and internal controls necessary to operate as a fund manager and that all use of System outputs is subject to Client's own review, judgment, and risk-management framework.

13.3Cap on Liability

The aggregate liability of each Party under this Agreement, whether in contract, tort (including negligence), strict liability, or otherwise, is limited to the total fees paid or payable by Client to Service Provider under this Agreement during the three (3) months immediately preceding the event giving rise to the claim.

13.4Excluded Damages

Neither Party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, loss of trading opportunities, market losses, loss of goodwill, loss of data (except as recoverable from backups per Section 11), or business interruption, even if advised of the possibility of such damages.

13.5Exclusions to Cap and Excluded Damages

Sections 13.3 and 13.4 do not apply to:

  1. breach of confidentiality obligations under Section 8;
  2. infringement of intellectual property rights;
  3. fraud, gross negligence, or willful misconduct;
  4. indemnification obligations under Section 14;
  5. liability that cannot be excluded or limited under applicable mandatory law.
Section 14

Indemnification

14.1Service Provider Indemnity

Service Provider shall defend, indemnify, and hold harmless Client from and against third-party claims to the extent arising from Service Provider's infringement of any third party's intellectual property rights through the Client Deliverables (excluding (i) infringement caused by Client-supplied materials, (ii) modifications made by Client or by third parties on Client's instruction, and (iii) use of the Client Deliverables in combination with materials not provided by Service Provider where the combination is the cause of infringement).

14.2Client Indemnity

Client shall defend, indemnify, and hold harmless Service Provider from and against third-party claims to the extent arising from (a) Client's use of the System's outputs in violation of applicable law, (b) inaccuracy of Client-supplied data (including position records, fund data, and the Mímir corpus), or (c) Client's investment, trading, or portfolio decisions.

14.3Indemnification Procedure

The Party seeking indemnification shall (a) give prompt written notice of the claim, (b) grant the indemnifying Party sole control of the defense and settlement (provided that no settlement adversely affecting the indemnified Party's rights may be entered without that Party's consent, not unreasonably withheld), and (c) provide reasonable cooperation at the indemnifying Party's expense.

Section 15

Compliance and Regulatory

15.1Current Phase — Research-Only

The Parties acknowledge that the System, in its initial scope, is an internal informational tool for Client's research operation. The System does not place orders, transmit trade instructions, hold or move client capital, or provide investment recommendations to third parties. Accordingly, the initial phases of the Project are not within the scope of regulated investment-services activities under Icelandic, German, or EU law as applied to Service Provider.

15.2Future Phases

If the Project's scope expands to include features that may bring the System within regulated activity — for example execution capability, automated order placement, advisory output to third parties, or capital movement — the Parties shall, before such scope expansion takes effect, conduct a regulatory compliance review and agree in writing on the additional measures required. Such measures may include licensing, registration, structural changes, additional indemnities, additional insurance, or commercial terms reflecting the change in risk profile.

15.3Compliance Out of Scope for Phase 1

Compliance certifications, regulatory audits, registrations with financial supervisory authorities (including Iceland's Fjármálaeftirlitið / FME and Germany's BaFin), and similar regulated-activity preparations are out of scope for the initial Project phases. Service Provider shall give Client reasonable notice if Service Provider becomes aware that any feature being built or maintained may push the System into regulated territory.

15.4Anti-Bribery and Sanctions

Each Party warrants that it shall comply with applicable anti-bribery, anti-corruption, and economic sanctions laws in performing this Agreement.

Section 16

Post-Termination Maintenance Option

16.1Election

At any time within thirty (30) days before or after the termination or expiration date, Client may elect, by written notice to Service Provider, to engage Service Provider for ongoing operation, hosting, monitoring, and maintenance of the System (the "Maintenance Services").

16.2Maintenance Fee

The fee for Maintenance Services (the "Maintenance Fee") is agreed in writing by the Parties at the time Maintenance Services commence, taking account of the composition of the System's tech stack at handover. As an indicative reference, Service Provider's expected Maintenance Fee for a stack consistent with the Indicative Maintenance Stack in Schedule F is approximately ISK 100,000 per month plus VAT. Where the actual stack at handover materially differs from the Indicative Maintenance Stack, the Maintenance Fee shall be adjusted to reflect the difference, on a basis to be agreed in good faith.

16.3What the Maintenance Fee Covers

The Maintenance Fee is all-inclusive for Service Provider's labor and the operation of services in the agreed tech stack, and shall not increase as a function of System usage volume, agent count, workflow count, data volume, or feature additions falling within the scope of this Section. It includes:

  1. operating, hosting (where Service Provider hosts components of the System), and monitoring the System in production;
  2. routine bug fixes, performance tuning, and minor improvements;
  3. software dependency updates, security patches, and platform-version upgrades for the System's components;
  4. adjustments to existing agents and workflows, including prompt revisions, parameter tuning, and minor scope refinements;
  5. configuration changes and minor feature additions consistent with the existing system architecture;
  6. reasonable response to operational incidents during business hours;
  7. monthly written status reporting at a level of detail mutually agreed.

16.4What the Maintenance Fee Does NOT Cover

The Maintenance Fee does not cover, and Client shall procure and pay directly for, the items in Schedule F.2 (Client-Procured Components), and the following are out of scope and require a separate written statement of work:

  1. substantial new modules — for example, addition of a fund (such as a crypto fund), a new market venue, or a new instrument class;
  2. new agent categories functionally distinct from those in the System at handover (for example, transitioning from research-only agents to execution-capable agents, paper-trading agents, or risk-management agents not present at handover);
  3. fundamental architectural rebuilds, framework migrations, or rewrites of more than thirty percent (30%) of the codebase;
  4. integration with new client back-office systems, broker APIs, or data providers not present at handover;
  5. migration of the System to a different hosting environment at Client's request;
  6. custom reporting, analytics, or visualization not part of the System at handover where development effort exceeds twenty (20) hours;
  7. compliance, audit, or regulatory work referenced in Section 15.2;
  8. knowledge transfer or training beyond reasonable operational documentation.

16.5Stack Adjustments During Maintenance

If the Parties agree to add a new service to the tech stack during Maintenance Services that creates ongoing operational obligations for Service Provider, the Parties shall discuss in good faith whether and how the Maintenance Fee should adjust. Service Provider shall not unilaterally raise the Maintenance Fee.

16.6Term

The maintenance engagement runs month-to-month, terminable by either Party on thirty (30) days' written notice.

16.7Service-Level Expectations

Maintenance Services are provided on a best-efforts basis during Service Provider's regular business hours. No specific service-level agreement applies unless separately documented. Service Provider undertakes to (a) acknowledge operational incidents reported in writing within one (1) business day, (b) restore service from outages caused by the System or Service Provider's operations using reasonable efforts, and (c) provide monthly written status.

16.8Service Provider's Right to Decline

Service Provider may decline to offer or continue Maintenance Services in its sole discretion. Decline does not prejudice Client's rights under this Agreement.

16.9No Right of First Refusal

Nothing in this Section grants Service Provider a right of first refusal or exclusivity.

16.10Continuity During Election Window

If Client elects per Section 16.1 prior to the termination date, Service Provider may continue operating the System during the election window at the then-current Service Fee, prorated daily, for up to thirty (30) days. If a maintenance engagement is not commenced within that period, the engagement terminates and Handover Deliverables transfer per Section 4.5.

Section 17

Force Majeure

17.1Force Majeure Event

Neither Party shall be liable for failure to perform, or delay in performance of, any obligation under this Agreement (other than payment obligations) caused by acts of God, war, terrorism, civil disturbance, natural disaster, government action, or other event beyond that Party's reasonable control. Such events expressly include outages of multiple inference providers occurring simultaneously and outages of multiple platform vendors (Railway, Supabase, n8n, or equivalents).

17.2Notice and Mitigation

The affected Party shall give prompt written notice of the force majeure event and shall use reasonable efforts to mitigate the impact and resume performance as soon as practicable.

17.3Termination Right

If a force majeure event continues for more than thirty (30) consecutive days, either Party may terminate this Agreement by written notice without further liability, except for accrued obligations and surviving provisions per Section 4.5.

Section 18

Assignment to Galdr ehf.

18.1No Assignment Without Consent

Except as provided in Section 18.2 and Section 18.3, neither Party may assign this Agreement without the other Party's prior written consent.

18.2Assignment to Galdr ehf.

Client consents in advance to Service Provider's assignment of this Agreement, in whole, to Galdr ehf. (an Icelandic einkahlutafélag in formation as of the Effective Date) upon issuance of Galdr ehf.'s registration number ("kennitala") by Iceland Companies Registry. Service Provider shall give Client written notice of the assignment, attaching evidence of the kennitala, and the assignment takes effect on the date of such notice. Following the assignment, Galdr ehf. assumes all of Service Provider's rights and obligations under this Agreement, and Service Provider in his personal capacity is released from future performance obligations, except for liabilities accrued prior to the assignment.

18.3Continuity

The terms of this Agreement, including the Service Fee, Term, all Schedules, and the Maintenance Option, continue without interruption upon assignment. Invoicing transitions from Service Provider's personal entity to Galdr ehf. on the effective date of the assignment, with VAT treatment adjusted as set forth in Section 5.4.

18.4Successor Entities

Either Party may assign this Agreement to a successor entity in connection with a merger, acquisition, or reorganization, on written notice and without consent, provided that the successor assumes all obligations under this Agreement.

Section 19

Notices

19.1Form

All notices under this Agreement shall be in writing and shall be sent by email (with delivery confirmation) or by recognized courier to the addresses set out in Schedule B, as updated from time to time by written notice.

19.2Effective Date of Notice

Notices are deemed received on (a) the date of delivery confirmation for email, or (b) the date of courier delivery.

Section 20

Governing Law and Disputes

20.1Governing Law

This Agreement is governed by and construed in accordance with the laws of Iceland, without regard to conflict-of-laws principles.

20.2Dispute Resolution

The Parties shall attempt in good faith to resolve any dispute arising out of or relating to this Agreement through direct negotiation between authorized representatives. If the dispute is not resolved within thirty (30) days, the Parties shall attempt to resolve it through mediation administered by a mediator agreed between them or, failing agreement, appointed by the Reykjavík District Court.

20.3Jurisdiction

If mediation does not resolve the dispute within sixty (60) days of commencement, either Party may bring the matter before the Reykjavík District Court (Héraðsdómur Reykjavíkur), which shall have exclusive jurisdiction.

20.4Equitable Relief

Notwithstanding Section 20.2, either Party may seek injunctive or other equitable relief from any court of competent jurisdiction in respect of breach or threatened breach of intellectual property rights or confidentiality obligations.

Section 21

General Provisions

21.1Entire Agreement

This Agreement, including all Schedules, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior agreements, negotiations, and understandings.

21.2Amendments

Any amendment to this Agreement must be in writing and signed by authorized representatives of both Parties. Roadmap amendments per Section 3.3 may be made by exchange of confirming emails between named representatives.

21.3Severability

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision shall be replaced by a valid provision that most nearly reflects the original intent.

21.4No Waiver

A Party's failure to enforce any provision of this Agreement is not a waiver of that or any other provision.

21.5Independent Contractors

The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment, or agency relationship.

21.6Counterparts and Electronic Signature

This Agreement may be executed in counterparts, each of which is an original, and may be signed electronically with the same legal effect as a handwritten signature.

21.7Language

This Agreement is executed in English. Should the Parties agree to prepare an Icelandic translation, the English version shall be controlling unless the Parties expressly agree otherwise in writing.Review note: subject to Service Provider's preference; can be flipped to Icelandic-controlling.

21.8Headings

Headings are for convenience only and do not affect interpretation.

21.9No Third-Party Beneficiaries

This Agreement does not confer rights on any third party.

Execution

Signatures

Service Provider

By: _______________________

Name: Boas [Surname]

Capacity: Sole-trader / Freiberufler, with intent to assign to Galdr ehf. per Section 18

Date: _______________________

Client

By: _______________________

Name: [CIO name], Viska sjóðir ehf.

Capacity: [title]

Date: _______________________

Schedule A

Roadmap

Note

This Schedule references the working roadmap documents previously shared. The Roadmap is directional, not a fixed set of deliverables, per Section 3.3.

The Project Roadmap is set out in the following companion documents:

Phase 1, as adapted by mutual understanding between the Parties, comprises:

  1. Three specialized agents — Performance & Narrative, Fundamental, and Technical — each with focused scope and non-overlapping responsibilities, integrated with the Mímir corpus via read-only access.
  2. Mímir, Client's existing research system, acting as the operator and synthesis layer across the three agents.
  3. A client portal hosting per-agent dashboards and providing a chat interface to Mímir.
  4. Periodic reports generated by the agents, accessible through the portal.
  5. Sprint-cadenced delivery, with a UI demo available early in the engagement and progressive feature enablement thereafter.
  6. Indicative timeline for Phase 1 build: approximately six to eight (6–8) weeks from the Effective Date, subject to the unblocking of dependencies on Client-Provided Resources, portfolio data integration, and the Viska Screener framework specification.

The Roadmap is reviewed monthly per Section 3.4 and may be amended in writing.

Schedule B

Service Provider Details

Service Provider (during bridge period)

Successor entity (post-incorporation)

Continuity

Notices addressed to Service Provider during the bridge period are valid; notices addressed to Galdr ehf. become valid upon assignment per Section 18.

Schedule C

Client-Provided Resources

The following are required for Service Provider's performance of the services. Client procures, maintains, and bears the cost of each. Client retains administrative ownership and grants Service Provider access for the duration of this Agreement.

C.1Claude Code subscription (or equivalent successor product from Anthropic), used by Service Provider as a development environment.
C.2OpenAI API key with usage limits sufficient for the System's runtime workload. Used by the System's agents at runtime for language-model inference.
C.3[If applicable] Anthropic API key, where the System's agents call Anthropic models at runtime, in addition to or in place of OpenAI.Review note: confirm whether agents call Anthropic in production.
C.4Market data feed (e.g., Alpaca, Polygon, IEX Cloud, Tiingo, or equivalent of comparable coverage and reliability). Required for the Performance & Narrative Agent and the Technical Agent.
C.5News data feed (e.g., Tiingo News, MarketAux, NewsAPI, or equivalent). Required for the Fundamental Agent.
C.6Macro economic calendar (e.g., tradingeconomics.com or equivalent). Required for the Fundamental Agent.
C.7Fundamental and valuation data feed (e.g., FMP, IEX, Tiingo, or equivalent). Required for the Fundamental Agent.
C.8Slack workspace (Client-owned), where the System publishes notifications and Mímir is reachable for chat.
C.9Backup destination — Client-owned cloud storage (e.g., a Client-owned Google Drive folder or a Client-owned Dropbox folder, designated in writing). Required per Section 11.1.

Client shall provide credentials, scope, and reasonable usage limits for each of the above. Client shall promptly inform Service Provider of changes.

Schedule D

Form of Invoice

A specimen invoice issued under this Agreement shall include:

A specimen template shall be agreed between the Parties prior to issuance of the first invoice.

Schedule E

Handover Deliverables

Upon termination per Section 4.5, Service Provider shall transfer the following:

E.1 Project Repositories — All Git repositories created specifically for the Project, including full commit history. Includes: source code (Mastra agent definitions, n8n workflow exports, UI source code), configurations, tests, deployment scripts, README files, internal documentation. Excludes: Pantheon framework code, Service Provider's other clients' code. Delivered via repository transfer to Client-owned hosting account or Git bundle file.
E.2 Client Database Snapshot — Full snapshot of the Project's dedicated database (Supabase project or equivalent), including schemas, records, materialized views, stored procedures, indexes, and operational/run logs. Delivered as SQL dump or platform-native export.
E.3 Project Documentation
  1. Architecture overview;
  2. Operational runbook (deployment, monitoring, common operational tasks);
  3. Data dictionary for the Client Database;
  4. Open-source dependency list with licenses;
  5. Required environment variables and secret types (without values);
  6. Known issues and limitations as of handover date;
  7. Recommended next steps for ongoing operation;
  8. Disaster Recovery procedure and backup-restore procedure.
E.4 Credentials and Access Inventory
  1. Status of Client-Provided Resources per Schedule C;
  2. Client-procured third-party services configured for the Project, with administrative-access transition steps;
  3. Service Provider's keys, tokens, and accounts used for the Project shall be revoked, not transferred.
E.5 Knowledge Transfer — Up to eight (8) hours of synchronous knowledge transfer included at no additional charge per Section 4.6. Recorded sessions (if Client requests recording) become Client's property subject to Section 8.
E.6 Excluded from Handover
  1. Service Provider's Pantheon development framework (not part of the deliverable);
  2. Service Provider's other clients' data, code, or infrastructure;
  3. Service Provider's internal tooling, planning documents, session records, or operational artifacts;
  4. Open-source components beyond their license obligations.
Schedule F

Indicative Maintenance Stack

Indicative basis for the Maintenance Fee referenced in Section 16.2. Composition at handover may vary.

F.1 Service Provider-Operated Components

Service Provider procures, operates, and bears the platform cost as part of the Maintenance Fee:

  1. Railway — hosting for the Mastra agent runtime and the user interface;
  2. n8n — workflow orchestration (self-hosted or platform);
  3. Supabase — database, storage, authentication (Project-dedicated instance);
  4. Cloudflare or comparable — DNS, TLS, CDN;
  5. Domain registration if Service Provider holds the domain on Client's behalf;
  6. Email/notification service of modest scale;
  7. Operational monitoring at a level appropriate to a best-efforts service expectation;
  8. Backup execution to Client-owned destination per Schedule C.9 and Section 11.

F.2 Client-Procured Components

Client procures, pays directly, and grants Service Provider access for operation: per Schedule C.

F.3 Materially Different Stack — Examples Triggering Maintenance Fee Adjustment per Section 16.2

RefAdjustment Trigger
F.3 (a)Addition of a separate hosting platform requiring distinct operational oversight
F.3 (b)Addition of compliance, audit, or security services requiring Service Provider's ongoing administrative work
F.3 (c)Addition of a second runtime environment (for example a staging copy operated alongside production)
F.3 (d)Removal of a Client-Procured component requiring Service Provider to absorb the cost

The fee adjustment, if any, is agreed in writing per Section 16.5.

F.4 Per-Client Isolation

The components in Section F.1 are provisioned per Client and isolated from Service Provider's other engagements at the platform level (separate Supabase project, separate n8n instance, separate Railway project, separate domain). At handover under Section 4.5, the entire stack transfers to Client without partitioning, redaction, or shared-resource extraction.

Schedule G

Security Best Practices and Gates

Service Provider's security measures referenced in Section 10 include the following, applied with reasonable adaptation as the System evolves and as platform capabilities permit:

RefCategoryControls
G.1 Authentication & Access Control Multi-factor authentication required on all Service Provider developer and operator accounts; named-user authentication for administrative access; no shared accounts; principle of least privilege for all roles; periodic review of access rights; revocation of access on personnel changes.
G.2 Credential Hygiene Secrets stored in dedicated secret stores (platform-managed environment variables, vault, or equivalent); secrets never committed to source-code repositories; secrets never written to logs or audit output; rotation of long-lived credentials on a defined schedule.
G.3 Transport Security TLS 1.2 or higher for all client-facing endpoints and inter-service communication; HSTS enforced on the client portal; modern cipher suites; deprecation of weak algorithms.
G.4 Network & Endpoint Controls Client portal protected by authenticated entry points; database direct-access disabled from public networks; access only via authenticated application paths or platform-managed connection pools; administrative interfaces restricted by IP allowlist or zero-trust gateway where reasonably available; rate limiting on public endpoints.
G.5 Database Hardening Row-level security policies enabled on the Client Database where the underlying platform supports them, scoped to ensure that only the System's authenticated processes can read or write Client data; separation of read-only roles from read-write roles; encryption at rest using platform-default mechanisms; audit logging of administrative database actions where the platform supports it.
G.6 Foreign Actor Defense Client portal authentication required for all data access; anonymous access disabled; geographic anomaly detection where the underlying platform supports it; failed-authentication rate limiting and lockout; rejection of unauthenticated database connections from public networks; monitoring of unusual access patterns; notification per Section 10.3 on suspected compromise.
G.7 Software Hygiene Timely application of security patches and dependency updates; periodic review of open-source components for known vulnerabilities; removal of unused dependencies and dead code paths.
G.8 Operational Logging Append-only operational logs for material System actions; retention for at least the term of this Agreement plus one year; logs accessible to Client through the client portal per Section 11; logs include authentication events, configuration changes, data-modifying agent runs, errors, and security-relevant events.
G.9 Backup & Recovery Backups per Section 11 written to Client-owned storage; backup integrity tested at least quarterly; documented restore procedure included in Schedule E.
G.10 Incident Response Notification within 72 hours of confirmed or reasonably suspected security incident per Section 10.3; containment, investigation, and remediation steps documented; post-incident report shared with Client within fourteen (14) days of remediation.
G.11 Personnel All personnel with access to Client Confidential Information bound by confidentiality obligations; background level appropriate to the nature of access (no formal background checks required at the current scale, subject to scaling-up as the engagement evolves).
Schedule H

Disaster Scenarios and Mitigations

Reasonably foreseeable disaster scenarios and Service Provider's mitigation approach. Schedule H is descriptive of design intent, not a service-level agreement, except where explicitly stated.

# Scenario Mitigation Recovery target
1 Client Database corruption or data loss Restore from most recent automated backup (Section 11.1) to a fresh Supabase project or schema; replay any reproducible operations from Project Repositories RPO ≤ 24h; recovery time best-efforts
2 Inference provider (e.g., OpenAI) outage Automatic switchover to alternative inference provider via OpenRouter or equivalent abstraction Best-efforts continuity; intermittent agent run failures may occur during switchover
3 Multiple inference providers down simultaneously Force majeure per Section 17; agent runs paused; portal remains available for static data No recovery target; resumes when at least one provider returns
4 Railway (or replacement hosting) outage Communication via portal or alternate channel; switch to vendor-recommended remediation; failover where reasonably available Subject to vendor outage duration
5 Supabase outage Communication; vendor remediation; reads may fall back to recent backup snapshot for read-only display Subject to vendor outage duration
6 n8n outage Re-trigger workflows after restoration; persisted state in Client Database means runs are resumable Subject to vendor outage duration
7 Repository host (e.g., GitHub) outage Project Repositories are mirrored on backup destination; deployments may continue from local clones during outage Subject to vendor outage duration
8 Compromise of a Service Provider credential Immediate revocation; rotation of the affected credential; investigation per Section 10.3 Notification within 72h
9 Compromise of a Client-Provided credential Service Provider notifies Client; Client rotates; Service Provider receives new credential Continuity dependent on Client rotation timing
10 Loss of single point of operator availability (e.g., Service Provider unavailability) Documentation in Schedule E.3 enables Client or third party to operate the System; Maintenance Option provides continuity if Client elects No specific recovery target during the bridge phase prior to Maintenance Option election
11 Client's own infrastructure compromise (Client-administered platforms) Out of Service Provider's control; Service Provider cooperates on detection and notification Client-owned response
12 Catastrophic loss of the System (e.g., total platform failure of Railway + Supabase simultaneously) Restore from backups (Project Repositories from Git remote and Client-owned mirror; Client Database from Client-owned backup destination); rebuild on alternative platforms Best-efforts; multi-day recovery acknowledged
End of Draft v0

This document is to be reviewed by Service Provider's tax advisor (skattaráðgjafi) and Iceland-licensed legal counsel (lögmaður) before issuance to Client. Specific items requiring professional confirmation are flagged in the body and in Section 5.4.