Service Agreement · April 2026

Viska Völundr Engagement

AI agent system development services
Service ProviderBoas [Surname] · Iceland-domiciled · Galdr ehf. (in formation)
ClientViska sjóðir ehf., kt. 471221-0900
Effective Date[DATE]
Initial TermThree (3) calendar months
Service
Provider
Boas [Surname], an individual domiciled in Iceland, kennitala [TBD], acting as a sole-trader service provider in the field of software development, with intent to assign this Agreement to Galdr ehf. (an Icelandic einkahlutafélag in formation as of the Effective Date) upon issuance of its registration number ("kennitala") by the Icelandic Companies Registry, in accordance with Section 18 below.
Client
Viska sjóðir ehf., kennitala 471221-0900, an Icelandic fund management company having its registered office at [address], Reykjavík, Iceland.
Reference
Each a "Party" and together the "Parties".
Section 1

Recitals

WHEREAS Client wishes to engage Service Provider for the design and ongoing iteration of an AI agent system supporting Client's research operation;

WHEREAS Service Provider is in the process of incorporating Galdr ehf., to which this Agreement is intended to be assigned upon incorporation;

NOW, THEREFORE, the Parties agree as follows.

Section 2

Definitions

In this Agreement, unless the context otherwise requires:

"Agreement"
means this service agreement, including all Schedules, as amended from time to time.
"Background IP"
means intellectual property owned, developed, or licensed by a Party prior to or independently of this Agreement.
"Client Database"
means the database (or databases) instantiated for the Project containing Client-specific data, schemas, run logs, and operational records.
"Client Deliverables"
means the configurations, code, prompts, schemas, integrations, and documentation specifically created for Client under this Agreement, as further described in Schedule E.
"Client-Provided Resources"
has the meaning set out in Section 6 and Schedule C.
"Confidential Information"
has the meaning set out in Section 8.
"Effective Date"
means [DATE].
"Handover Deliverables"
means the items specified in Schedule E.
"Indicative Maintenance Stack"
means the tech stack described in Schedule F.
"Maintenance Fee"
has the meaning set out in Section 16.
"Maintenance Services"
has the meaning set out in Section 16.
"Project"
means the design, development, and ongoing iteration of an AI agent system for Client's research operation, performed under this Agreement.
"Project Repositories"
means the source-code repositories created specifically for the Project.
"Roadmap"
means the working roadmap document attached as Schedule A, as amended in writing from time to time per Section 3.3.
"Service Fee"
has the meaning set out in Section 5.1.
"System"
means the AI agent system, including its agents, workflows, user interface, database, configurations, and runtime infrastructure, designed and developed for Client under this Agreement.
"VAT"
means Icelandic value-added tax (virðisaukaskattur, VSK).
Section 3

Services

3.1Engagement

Service Provider shall provide AI agent system development services to Client in accordance with the Roadmap and this Agreement.

3.2Standard of Performance

Service Provider shall perform the services with the degree of skill, care, and diligence reasonably expected of a qualified professional in the field of AI software development. Service Provider does not guarantee any specific outcome, performance metric, profit, return, system uptime, or completion date.

3.3Roadmap

The Roadmap describes the Parties' shared objectives and indicative timeline as of the Effective Date. The Roadmap is directional, not contractual. The Parties may amend the Roadmap by written agreement (email confirmation between named representatives is sufficient) at any time. Amendments supersede the corresponding portions of the Roadmap on a going-forward basis.

3.4Monthly Review

The Parties shall meet on or about the first business day of each calendar month to review progress against the Roadmap, discuss adjustments, and document priorities for the upcoming month. Documented outcomes of the monthly review constitute Roadmap amendments per Section 3.3.

3.5No Acceptance Gate

The Parties acknowledge that the Project is iterative and that no deliverable is conditioned upon Client's formal acceptance. Client's sole remedy for dissatisfaction with the work is termination per Section 4.3.

3.6Best-Efforts; No Warranty of Outcome

Service Provider's obligation is to perform services on a best-efforts basis. Service Provider does not warrant that any particular feature will function as initially conceived, that any particular date will be met, or that any particular benefit will be realised.

Section 4

Term and Termination

4.1Effective Date

This Agreement commences on the Effective Date.

4.2Initial Term

The initial term is three (3) calendar months from the Effective Date (the "Initial Term"). Following the Initial Term, this Agreement continues on a month-to-month basis until terminated in accordance with this Section 4.

4.3Termination for Convenience

Either Party may terminate this Agreement at any time, including during the Initial Term, by providing thirty (30) days' written notice to the other Party. No cause is required.

4.4Termination for Cause

Either Party may terminate this Agreement immediately upon written notice if the other Party (a) materially breaches this Agreement and fails to cure within fourteen (14) days of written notice describing the breach, or (b) becomes insolvent, files for bankruptcy, or ceases regular business operations.

4.5Effect of Termination

Upon termination or expiration of this Agreement for any reason:

  1. Service Provider shall issue a final invoice prorated to the termination date, payable per Section 5.2.
  2. Within fourteen (14) days after the termination date, Service Provider shall transfer the Handover Deliverables to Client per Schedule E and Section 7.
  3. Service Provider shall revoke its access to the Client-Provided Resources and any Client-controlled systems within five (5) business days after the handover is complete, or immediately upon Client's request, whichever is earlier.
  4. Each Party shall return or destroy the other Party's Confidential Information per Section 8, except (i) one archival copy may be retained for legal, audit, or backup-recovery purposes, and (ii) Service Provider may retain Client Deliverables to the extent reasonably necessary to perform Maintenance Services if elected by Client per Section 16.
  5. The following Sections survive termination: 7 (Intellectual Property), 8 (Confidentiality), 9 (Data Protection), 10 (Security), 11 (Backups and Audit), 13 (Liability), 14 (Indemnification), 15 (Compliance), 16 (Maintenance Option), 18 (Assignment), 20 (Governing Law and Disputes), 21 (General Provisions), and this Section 4.5.

4.6Handover Cooperation

Both Parties shall cooperate in good faith to effect the handover. Service Provider shall provide up to eight (8) hours of synchronous knowledge-transfer assistance at no additional charge. Further assistance is billable at Service Provider's then-current hourly rate. Client shall procure its own infrastructure (Git hosting, database hosting, credentials, third-party platform accounts) sufficient to receive the Handover Deliverables prior to the handover date.

Section 5

Fees and Payment

5.1Service Fee

Client shall pay Service Provider a monthly fee of ISK 1,200,000 (one million two hundred thousand Icelandic krónur) plus VAT (the "Service Fee"). The Service Fee covers Service Provider's professional services and all infrastructure, tooling, hosting, third-party software, and operational costs incurred by Service Provider in performing the services, except as set out in Section 6 (Client-Provided Resources).

5.2Invoicing

Service Provider shall issue an invoice on or about the first business day of each calendar month for that month's services. Invoices are payable within fourteen (14) days of the invoice date. Late payments accrue interest at the rate set out in Icelandic Act no. 38/2001 on Interest and Price Indexation.

5.3Currency

Invoices are denominated in ISK.

5.4VAT

Invoices issued under this Agreement are subject to Icelandic VAT at the prevailing rate (currently 24%), added to invoiced amounts. Service Provider's VAT registration status (sole-trader during the bridge period; Galdr ehf. after the assignment per Section 18) shall be reflected on each invoice with the appropriate VSK number and entity name. The Parties shall cooperate on reasonable invoice-format adjustments associated with the assignment.

5.5No Set-Off

Client shall pay all invoiced amounts in full without set-off, counterclaim, or deduction, except as required by applicable law.

Section 6

Client-Provided Resources

6.1Resources Required

Client shall procure, maintain, and bear all costs of the Client-Provided Resources specified in Schedule C, which are required for Service Provider's performance of the services.

6.2Access Grant

Client grants Service Provider access to the Client-Provided Resources for the duration of this Agreement. Service Provider shall use such access solely for performance of this Agreement and shall not use the Client-Provided Resources for any other purpose.

6.3Administrative Ownership

Client retains administrative ownership of the Client-Provided Resources. Service Provider shall not transfer, share, or expose access credentials for Client-Provided Resources to any third party.

6.4Usage Monitoring

Service Provider shall monitor its use of Client-Provided Resources and shall promptly notify Client if usage trends unexpectedly toward limits or budget thresholds.

6.5Liability for Usage Costs

Client bears all usage costs for Client-Provided Resources arising from operation of the System within reasonable parameters. Service Provider is liable for usage costs caused by Service Provider's gross negligence or willful misconduct, subject to the cap in Section 13.3.

6.6Risk of Insufficient Capacity

Client bears the risk of insufficient capacity, rate-limit exhaustion, or service interruption attributable to the Client-Provided Resources.

Section 7

Intellectual Property

7.1Background IP

Each Party retains all rights in its Background IP. Service Provider's Background IP includes (without limitation) Service Provider's internal development environment, generic agent patterns, reusable skills, and development tooling. Client's Background IP includes (without limitation) Client's fund data, the Mímir corpus, the Viska Screener framework, Client's brand assets, and Client's pre-existing systems.

7.2Client Deliverables

Subject to Section 7.3 and Client's payment in full of invoiced fees, Service Provider assigns to Client all rights in the Client Deliverables. Client owns all data the System processes for Client.

7.3Service Provider Retained Rights

Service Provider retains:

  1. all Background IP. Service Provider's internal development environment is used to design, build, and test the System but forms no part of the Client Deliverables. No internal-framework code or shared infrastructure references shall be present in the Client Deliverables.
  2. all general knowledge, methodologies, design techniques, architectural patterns, and non-Client-specific learnings gained during the engagement, which Service Provider may apply to other engagements and to the evolution of Service Provider's own products;
  3. ownership of any third-party open-source components incorporated into the System, which retain their respective licenses.

7.4Composition of the System

The System delivered under this Agreement consists solely of (i) configurations and code authored specifically for the Project, (ii) third-party open-source and licensed components used as runtime dependencies, and (iii) Project-specific data, schemas, and operational records.

7.5Mímir and Viska Screener

The Mímir corpus and the Viska Screener framework are Client's Background IP. Service Provider's access during the Project is read-only for integration purposes only.

7.6Repository Ownership During Term

The Project Repositories are hosted by Service Provider during the Term on infrastructure controlled by Service Provider, isolated from other Service Provider engagements at the repository level. Client receives read access on request during the Term.

7.7Repository Transfer at Termination

Upon termination, Service Provider shall transfer ownership of the Project Repositories to Client by either (i) initiating a repository transfer to Client's hosting account on the same platform, or (ii) providing Client with a complete Git bundle for Client's import. Method is at Service Provider's discretion unless the Parties agree otherwise.

7.8Database Transfer at Termination

Service Provider shall provide Client with a complete snapshot of the Client Database in a standard portable format. The Client Database is operated on infrastructure dedicated to the Project, such that the snapshot transfers in full without partitioning or redaction.

7.9License-Back to Service Provider

Notwithstanding the assignment in Section 7.2, Client grants Service Provider a perpetual, irrevocable, worldwide, non-exclusive, royalty-free license to use the general knowledge, methodologies, and non-Client-specific techniques developed during the Project for the purpose of evolving Service Provider's products and serving other clients. This license does not extend to Client's Confidential Information, Client-specific configurations or code, fund data, trading strategy, the Mímir corpus, the Viska Screener framework, or any artifact identifiable as belonging to Client. Service Provider shall not represent that Client endorses or is associated with any subsequent Service Provider product.

7.10Open-Source Notice

Service Provider shall provide Client with a list of all open-source components used in the Client Deliverables and their respective licenses as part of the Project Documentation under Schedule E. Client's use of such components is governed by their original licenses.

Section 8

Confidentiality

8.1Definition

"Confidential Information" means non-public information disclosed by one Party to the other in connection with this Agreement, including (without limitation) Client's fund positions, NAV history, trading strategy, LP information, the contents of the Mímir corpus, the Viska Screener framework, and Client's pre-existing systems; and Service Provider's technical architecture, source code, methodologies, pricing, and internal tooling.

8.2Obligations

Each Party shall (a) hold the other's Confidential Information in strict confidence, (b) use it only to perform under this Agreement, (c) limit access to personnel and advisors with a need to know who are bound by confidentiality obligations at least as protective as this Section, and (d) protect it with the same degree of care it uses for its own Confidential Information of similar sensitivity, but no less than reasonable care.

8.3Exclusions

Confidential Information does not include information that (a) is or becomes publicly known through no fault of the receiving Party, (b) was known to the receiving Party prior to disclosure without confidentiality obligation, (c) is rightfully received from a third party without confidentiality obligation, or (d) is independently developed without use of the disclosing Party's Confidential Information.

8.4Compelled Disclosure

The receiving Party may disclose Confidential Information to the extent required by law, regulation, or court order, provided it gives the disclosing Party prompt written notice (where lawful) and cooperates with reasonable efforts to limit the scope of disclosure.

8.5Survival

Confidentiality obligations survive termination of this Agreement for five (5) years, except for trade secrets and Client's investment data, which remain confidential for as long as they retain trade-secret or sensitive-financial status under applicable law.

Section 9

Data Protection

9.1Compliance

Each Party shall comply with applicable data protection laws, including the Icelandic Act on the Protection of Privacy as regards the Processing of Personal Data and Iceland's implementation of the EU General Data Protection Regulation (GDPR).

9.2Personal Data

The Parties acknowledge that the Project, in its initial scope, primarily processes commercial fund data and is not expected to process material volumes of personal data. To the extent personal data is processed, the Parties shall enter into a Data Processing Agreement in a form to be agreed prior to such processing commencing.

9.3Data Residency

Service Provider shall use reasonable efforts to ensure that Client Database storage and processing occur within the European Economic Area (EEA). Cross-border processing outside the EEA, where necessary for service operation, shall be subject to appropriate safeguards.

9.4Data Subject Requests

The Parties shall cooperate on a reasonable basis to respond to requests by data subjects exercising rights under applicable data-protection law.

Section 10

Security

10.1Service Provider Security Practices

Service Provider shall implement and maintain reasonable security measures appropriate to the nature of the data processed, in accordance with the practices set out in Schedule G, including access control on the principle of least privilege, multi-factor authentication on administrative accounts, secrets isolation, transport encryption, and authenticated entry points to the client portal and Client Database.

10.2Foreign Actor Defense

Service Provider shall implement controls reasonably designed to detect and prevent unauthorised access by external actors, including gateway-level authentication for the client portal, row-level security policies on the Client Database where the underlying platform supports them, rate limiting on public endpoints, and rejection of unauthenticated database connections from public networks.

10.3Incident Notification

Service Provider shall notify Client without undue delay (and in any event within seventy-two (72) hours) after becoming aware of any actual or reasonably suspected security incident materially affecting the Client Database, the System's authentication, or Client's Confidential Information. The notification shall describe the nature of the incident, the data and systems affected, the steps taken to contain it, and proposed remediation.

10.4Client Cooperation

Client shall cooperate in good faith with Service Provider's security measures, including procuring its own access credentials promptly, applying multi-factor authentication on Client-administered systems where available, and notifying Service Provider promptly of suspected compromise of Client's own accounts.

10.5No Warranty of Absolute Security

Service Provider does not warrant that the System or its operations are immune to compromise. This Section sets out a standard of reasonable care, not a guarantee of outcome.

Section 11

Backups and Audit

11.1Backups

Service Provider shall configure automated backups of the Client Database and the Project Repositories with the following characteristics:

  1. Frequency: at least daily for the Client Database; on every commit for the Project Repositories.
  2. Destination: backups shall be written to a Client-owned cloud storage location designated in writing by Client (for example a Client-owned Google Drive folder or Client-owned Dropbox folder), in addition to any backups provided natively by the underlying platforms.
  3. Retention: at least thirty (30) days of daily Database backups; full Repository history.
  4. Encryption at rest: backups shall be encrypted at rest using industry-standard encryption.
  5. Restoration: Service Provider shall test restoration from backup at least once per calendar quarter and document the result in the operational log.

11.2Client Access to Backups

Because backups are written to Client-owned storage, Client retains independent access to backup data at all times, including after termination. Service Provider shall not be the sole holder of backup material.

11.3Audit Visibility Through Portal

Service Provider shall make operational audit information visible to Client through the client portal that forms part of the System. Such information shall include System health indicators, run logs for agent invocations, recent deployment and configuration-change events, and notable security events recorded by the System.

11.4Out-of-Portal Audit Requests

On reasonable written request, Service Provider shall provide further audit information not available through the portal, subject to reasonable scope and a reasonable response window.

Section 12

Resilience and Disaster Recovery

12.1Inference Provider Resilience

The System is designed to switch between language-model inference providers (for example via OpenRouter or equivalent abstraction) such that an outage at any single inference provider does not, in itself, cause a System-wide outage. Service Provider's commitment in this Section is best-efforts.

12.2Platform Outages

The System depends on third-party platforms for which Service Provider is not the operator. In the event of an outage of any such platform, Service Provider shall communicate the status to Client through the client portal or other agreed channel, follow the platform vendor's recommended remediation, and where reasonable switch to a fallback configuration. Service Provider is not liable for the duration or consequences of platform outages outside Service Provider's reasonable control.

12.3Disaster Scenarios

The Parties acknowledge the disaster scenarios and corresponding mitigation approaches set out in Schedule H. Schedule H reflects the System's design assumptions and is descriptive, not a service-level commitment.

12.4Recovery Point Objective

In the event of catastrophic data loss attributable to the Client Database, Service Provider shall restore from the most recent available backup on a best-efforts basis. Recovery point objective is no greater than twenty-four (24) hours under normal operating conditions.

12.5No SLA Beyond This Section

This Section sets best-efforts commitments. No service-level agreement (uptime percentage, response time, recovery time) applies unless separately documented in writing and signed by both Parties.

Section 13

Liability

13.1No Investment Advice; No Fiduciary Relationship

Defensive Clause · Critical

The services and any outputs from the System are informational tools for Client's internal use. Nothing in this Agreement constitutes investment advice, financial advice, regulatory advice, or a recommendation to buy, sell, or hold any security or financial instrument. All investment, trading, and portfolio decisions are made solely by Client and its personnel. Service Provider is not registered or regulated as an investment advisor, broker-dealer, or financial intermediary in any jurisdiction.

No fiduciary, agency, or advisory relationship is created by this Agreement.

13.2Client's Responsibility

Client confirms that it has the expertise, regulatory permissions, and internal controls necessary to operate as a fund manager, and that all use of System outputs is subject to Client's own review, judgment, and risk-management framework.

13.3Cap on Liability

The aggregate liability of each Party under this Agreement, whether in contract, tort (including negligence), strict liability, or otherwise, is limited to the total fees paid or payable by Client to Service Provider under this Agreement during the three (3) months immediately preceding the event giving rise to the claim.

13.4Excluded Damages

Neither Party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, loss of trading opportunities, market losses, loss of goodwill, loss of data (except as recoverable from backups per Section 11), or business interruption, even if advised of the possibility of such damages.

13.5Exclusions to Cap and Excluded Damages

Sections 13.3 and 13.4 do not apply to:

  1. breach of confidentiality obligations under Section 8;
  2. infringement of intellectual property rights;
  3. fraud, gross negligence, or willful misconduct;
  4. indemnification obligations under Section 14;
  5. liability that cannot be excluded or limited under applicable mandatory law.
Section 14

Indemnification

14.1Service Provider Indemnity

Service Provider shall defend, indemnify, and hold harmless Client from and against third-party claims to the extent arising from Service Provider's infringement of any third party's intellectual property rights through the Client Deliverables, excluding (i) infringement caused by Client-supplied materials, (ii) modifications made by Client or third parties on Client's instruction, and (iii) use of the Client Deliverables in combination with materials not provided by Service Provider where the combination is the cause of infringement.

14.2Client Indemnity

Client shall defend, indemnify, and hold harmless Service Provider from and against third-party claims to the extent arising from (a) Client's use of the System's outputs in violation of applicable law, (b) inaccuracy of Client-supplied data, or (c) Client's investment, trading, or portfolio decisions.

14.3Indemnification Procedure

The Party seeking indemnification shall (a) give prompt written notice of the claim, (b) grant the indemnifying Party sole control of the defence and settlement (provided that no settlement adversely affecting the indemnified Party's rights may be entered without that Party's consent, not unreasonably withheld), and (c) provide reasonable cooperation at the indemnifying Party's expense.

Section 15

Compliance and Regulatory

15.1Current Scope — Research-Only

The Parties acknowledge that the System, in its initial scope, is an internal informational tool. The System does not place orders, transmit trade instructions, hold or move client capital, or provide investment recommendations to third parties. Accordingly, the initial Project is not within the scope of regulated investment-services activities.

15.2Future Scope Expansion

If the Project's scope expands to include features that may bring the System within regulated activity — for example execution capability, automated order placement, advisory output to third parties, or capital movement — the Parties shall, before such scope expansion takes effect, conduct a regulatory compliance review and agree in writing on the additional measures required, which may include licensing, registration, structural changes, additional indemnities, additional insurance, or commercial terms reflecting the change in risk profile.

15.3Compliance Out of Scope for the Initial Project

Compliance certifications, regulatory audits, registrations with financial supervisory authorities, and similar regulated-activity preparations are out of scope for the initial Project. Service Provider shall give Client reasonable notice if Service Provider becomes aware that any feature being built or maintained may push the System into regulated territory.

15.4Anti-Bribery and Sanctions

Each Party warrants that it shall comply with applicable anti-bribery, anti-corruption, and economic sanctions laws.

Section 16

Post-Termination Maintenance Option

16.1Election

At any time within thirty (30) days before or after the termination or expiration date, Client may elect, by written notice to Service Provider, to engage Service Provider for ongoing operation, hosting, monitoring, and maintenance of the System (the "Maintenance Services").

16.2Maintenance Fee

The fee for Maintenance Services (the "Maintenance Fee") is agreed in writing by the Parties at the time Maintenance Services commence, taking account of the composition of the System's tech stack at handover. As an indicative reference, Service Provider's expected Maintenance Fee for a stack consistent with the Indicative Maintenance Stack in Schedule F is approximately ISK 100,000 per month plus VAT. Where the actual stack at handover materially differs from the Indicative Maintenance Stack, the Maintenance Fee shall be adjusted to reflect the difference, on a basis to be agreed in good faith.

16.3What the Maintenance Fee Covers

The Maintenance Fee is all-inclusive for Service Provider's labour and the operation of services in the agreed tech stack, and shall not increase as a function of System usage volume, agent count, workflow count, data volume, or feature additions falling within the scope of this Section. It includes:

  1. operating, hosting (where Service Provider hosts components of the System), and monitoring the System in production;
  2. routine bug fixes, performance tuning, and minor improvements;
  3. software dependency updates, security patches, and platform-version upgrades;
  4. adjustments to existing agents and workflows, including prompt revisions, parameter tuning, and minor scope refinements;
  5. configuration changes and minor feature additions consistent with the existing system architecture;
  6. reasonable response to operational incidents during business hours;
  7. monthly written status reporting at a level of detail mutually agreed.

16.4What the Maintenance Fee Does NOT Cover

The Maintenance Fee does not cover, and Client shall procure and pay directly for, the items in Schedule F.2 (Client-Procured Components). The following are out of scope and require a separate written statement of work:

  1. substantial new modules — for example, addition of a new fund, a new market venue, or a new instrument class;
  2. new agent categories functionally distinct from those in the System at handover;
  3. fundamental architectural rebuilds, framework migrations, or rewrites of more than thirty percent (30%) of the codebase;
  4. integration with new client back-office systems, broker APIs, or data providers not present at handover;
  5. migration of the System to a different hosting environment at Client's request;
  6. custom reporting, analytics, or visualization not part of the System at handover where development effort exceeds twenty (20) hours;
  7. compliance, audit, or regulatory work referenced in Section 15.2;
  8. knowledge transfer or training beyond reasonable operational documentation.

16.5Stack Adjustments During Maintenance

If the Parties agree to add a new service to the tech stack during Maintenance Services that creates ongoing operational obligations for Service Provider, the Parties shall discuss in good faith whether and how the Maintenance Fee should adjust. Service Provider shall not unilaterally raise the Maintenance Fee.

16.6Term

The maintenance engagement runs month-to-month, terminable by either Party on thirty (30) days' written notice.

16.7Service-Level Expectations

Maintenance Services are provided on a best-efforts basis during Service Provider's regular business hours. No specific service-level agreement applies unless separately documented. Service Provider shall (a) acknowledge operational incidents reported in writing within one (1) business day, (b) restore service from outages caused by the System or Service Provider's operations using reasonable efforts, and (c) provide monthly written status.

16.8Service Provider's Right to Decline

Service Provider may decline to offer or continue Maintenance Services in its sole discretion. Decline does not prejudice Client's rights under this Agreement.

16.9No Right of First Refusal

Nothing in this Section grants Service Provider a right of first refusal or exclusivity. Client may engage any third party for ongoing operation of the System after termination at Client's discretion.

16.10Continuity During Election Window

If Client elects per Section 16.1 prior to the termination date, Service Provider may continue operating the System during the election window at the then-current Service Fee, prorated daily, for up to thirty (30) days. If a maintenance engagement is not commenced within that period, the engagement terminates and Handover Deliverables transfer per Section 4.5.

Section 17

Force Majeure

17.1Force Majeure Event

Neither Party shall be liable for failure to perform, or delay in performance of, any obligation under this Agreement (other than payment obligations) caused by acts of God, war, terrorism, civil disturbance, natural disaster, government action, or other event beyond that Party's reasonable control. Such events expressly include simultaneous outages of multiple inference providers and outages of multiple platform vendors.

17.2Notice and Mitigation

The affected Party shall give prompt written notice of the force majeure event and shall use reasonable efforts to mitigate the impact and resume performance as soon as practicable.

17.3Termination Right

If a force majeure event continues for more than thirty (30) consecutive days, either Party may terminate this Agreement by written notice without further liability, except for accrued obligations and surviving provisions per Section 4.5.

Section 18

Assignment to Galdr ehf.

18.1No Assignment Without Consent

Except as provided in Sections 18.2 and 18.4, neither Party may assign this Agreement without the other Party's prior written consent.

18.2Assignment to Galdr ehf.

Client consents in advance to Service Provider's assignment of this Agreement, in whole, to Galdr ehf. upon issuance of Galdr ehf.'s kennitala by Iceland Companies Registry. Service Provider shall give Client written notice of the assignment, attaching evidence of the kennitala, and the assignment takes effect on the date of such notice. Following the assignment, Galdr ehf. assumes all of Service Provider's rights and obligations under this Agreement, and Service Provider in his personal capacity is released from future performance obligations, except for liabilities accrued prior to the assignment.

18.3Continuity

The terms of this Agreement, including the Service Fee, Term, all Schedules, and the Maintenance Option, continue without interruption upon assignment. Invoicing transitions from Service Provider's personal entity to Galdr ehf. on the effective date of the assignment.

18.4Successor Entities

Either Party may assign this Agreement to a successor entity in connection with a merger, acquisition, or reorganisation, on written notice and without consent, provided that the successor assumes all obligations under this Agreement.

Section 19

Notices

19.1Form

All notices under this Agreement shall be in writing and shall be sent by email (with delivery confirmation) or by recognised courier to the addresses set out in Schedule B, as updated from time to time by written notice.

19.2Effective Date of Notice

Notices are deemed received on (a) the date of delivery confirmation for email, or (b) the date of courier delivery.

Section 20

Governing Law and Disputes

20.1Governing Law

This Agreement is governed by and construed in accordance with the laws of Iceland, without regard to conflict-of-laws principles.

20.2Dispute Resolution

The Parties shall attempt in good faith to resolve any dispute arising out of or relating to this Agreement through direct negotiation between authorised representatives. If the dispute is not resolved within thirty (30) days, the Parties shall attempt to resolve it through mediation administered by a mediator agreed between them or, failing agreement, appointed by the Reykjavík District Court.

20.3Jurisdiction

If mediation does not resolve the dispute within sixty (60) days of commencement, either Party may bring the matter before the Reykjavík District Court (Héraðsdómur Reykjavíkur), which shall have exclusive jurisdiction.

20.4Equitable Relief

Notwithstanding Section 20.2, either Party may seek injunctive or other equitable relief from any court of competent jurisdiction in respect of breach or threatened breach of intellectual property rights or confidentiality obligations.

Section 21

General Provisions

21.1Entire Agreement

This Agreement, including all Schedules, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior agreements, negotiations, and understandings.

21.2Amendments

Any amendment to this Agreement must be in writing and signed by authorised representatives of both Parties. Roadmap amendments per Section 3.3 may be made by exchange of confirming emails between named representatives.

21.3Severability

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision shall be replaced by a valid provision that most nearly reflects the original intent.

21.4No Waiver

A Party's failure to enforce any provision of this Agreement is not a waiver of that or any other provision.

21.5Independent Contractors

The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment, or agency relationship.

21.6Counterparts and Electronic Signature

This Agreement may be executed in counterparts, each of which is an original, and may be signed electronically with the same legal effect as a handwritten signature.

21.7Language

This Agreement is executed in [English / Icelandic]. If the Parties prepare a translation, the executed-language version shall be controlling unless the Parties expressly agree otherwise in writing.

21.8Headings

Headings are for convenience only and do not affect interpretation.

21.9No Third-Party Beneficiaries

This Agreement does not confer rights on any third party.

Execution

Signatures

Service Provider

By: _______________________

Name: Boas [Surname]

Capacity: Sole-trader, with intent to assign to Galdr ehf. per Section 18

Date: _______________________

Client

By: _______________________

Name: [name], Viska sjóðir ehf.

Capacity: [title]

Date: _______________________

Schedule A

Roadmap

The Project Roadmap consists of the working roadmap documents shared between the Parties prior to execution of this Agreement, including the engineering blueprint and the build specification covering the initial project scope. The Roadmap is reviewed monthly per Section 3.4 and may be amended in writing. The Roadmap is directional and does not impose fixed-deliverable obligations.

Schedule B

Service Provider Details

Service Provider (during bridge period)

Successor entity (post-incorporation)

Continuity

Notices addressed to Service Provider during the bridge period are valid; notices addressed to Galdr ehf. become valid upon assignment per Section 18.

Schedule C

Client-Provided Resources

The following are required for Service Provider's performance of the services. Client procures, maintains, and bears the cost of each. Client retains administrative ownership and grants Service Provider access for the duration of this Agreement.

C.1Claude Code subscription (or equivalent successor product), used by Service Provider as a development environment.
C.2OpenAI API key with usage limits sufficient for the System's runtime workload.
C.3Anthropic API key, where the System's agents call Anthropic models at runtime.
C.4Market data feed (e.g., Alpaca, Polygon, IEX Cloud, Tiingo, or equivalent).
C.5News data feed (e.g., Tiingo News, MarketAux, NewsAPI, or equivalent).
C.6Macro economic calendar (e.g., tradingeconomics.com or equivalent).
C.7Fundamental and valuation data feed (e.g., FMP, IEX, Tiingo, or equivalent).
C.8Slack workspace (Client-owned).
C.9Backup destination — Client-owned cloud storage (Google Drive folder, Dropbox folder, or equivalent), designated in writing per Section 11.1.

Client shall provide credentials, scope, and reasonable usage limits for each.

Schedule D

Form of Invoice

A specimen invoice issued under this Agreement shall include:

A specimen template shall be agreed between the Parties prior to issuance of the first invoice.

Schedule E

Handover Deliverables

Upon termination per Section 4.5, Service Provider shall transfer the following:

E.1 Project Repositories — All Git repositories created specifically for the Project, including full commit history; source code, configurations, tests, deployment scripts, README files, and internal documentation. Delivered via repository transfer to Client-owned hosting account or Git bundle file.
E.2 Client Database Snapshot — Full snapshot of the Project's dedicated database, including schemas, records, materialized views, stored procedures, indexes, and operational/run logs. Delivered as SQL dump or platform-native export.
E.3 Project Documentation — architecture overview; operational runbook; data dictionary; open-source dependency list with licenses; required environment variables and secret types (without values); known issues and limitations as of handover date; recommended next steps for ongoing operation; disaster recovery and backup-restore procedures.
E.4 Credentials and Access Inventory — status of Client-Provided Resources per Schedule C; Client-procured third-party services configured for the Project, with administrative-access transition steps. Service Provider's keys, tokens, and accounts used for the Project shall be revoked, not transferred.
E.5 Knowledge Transfer — Up to eight (8) hours of synchronous knowledge transfer included at no additional charge per Section 4.6. Recorded sessions (if Client requests recording) become Client's property subject to Section 8.
E.6 Excluded from Handover — Service Provider's Background IP and internal development environment; Service Provider's other clients' data, code, or infrastructure; Service Provider's internal tooling, planning documents, session records, or operational artifacts; open-source components beyond their license obligations.
Schedule F

Indicative Maintenance Stack

Indicative basis for the Maintenance Fee referenced in Section 16.2. Composition at handover may vary.

F.1 Service Provider-Operated Components

Service Provider procures, operates, and bears the platform cost as part of the Maintenance Fee:

  1. Application hosting (e.g., Railway) — agent runtime and user interface;
  2. Workflow orchestration (e.g., n8n);
  3. Database, storage, and authentication (e.g., Supabase, Project-dedicated instance);
  4. DNS, TLS, and CDN (e.g., Cloudflare);
  5. Domain registration if Service Provider holds the domain on Client's behalf;
  6. Email or notification service of modest scale;
  7. Operational monitoring at a level appropriate to a best-efforts service expectation;
  8. Backup execution to Client-owned destination per Schedule C.9 and Section 11.

F.2 Client-Procured Components

Per Schedule C.

F.3 Materially Different Stack — Examples Triggering Maintenance Fee Adjustment per Section 16.2

RefAdjustment Trigger
F.3 (a)Addition of a separate hosting platform requiring distinct operational oversight
F.3 (b)Addition of compliance, audit, or security services requiring Service Provider's ongoing administrative work
F.3 (c)Addition of a second runtime environment (e.g., a staging copy operated alongside production)
F.3 (d)Removal of a Client-Procured component requiring Service Provider to absorb the cost

The fee adjustment, if any, is agreed in writing per Section 16.5.

F.4 Per-Client Isolation

The components in Section F.1 are provisioned per Client and isolated from Service Provider's other engagements at the platform level (separate database project, separate orchestration instance, separate hosting project, separate domain). At handover under Section 4.5, the entire stack transfers to Client without partitioning, redaction, or shared-resource extraction.

Schedule G

Security Practices

Service Provider's security measures referenced in Section 10:

RefCategoryControls
G.1 Authentication & Access Control Multi-factor authentication on all Service Provider administrative accounts; named-user authentication (no shared accounts); principle of least privilege; access reviewed and revoked on personnel changes.
G.2 Credential Hygiene Secrets stored in dedicated secret stores or platform-managed environment variables; secrets never committed to source-code repositories or written to logs; periodic rotation of long-lived credentials.
G.3 Transport Security TLS 1.2 or higher for all client-facing endpoints and inter-service communication; HSTS enforced on the client portal; modern cipher suites; deprecation of weak algorithms.
G.4 Network & Endpoint Controls Authenticated entry points to the client portal; database direct-access disabled from public networks; administrative interfaces restricted by IP allowlist or zero-trust gateway where reasonably available; rate limiting on public endpoints.
G.5 Database Hardening Row-level security policies on the Client Database where the underlying platform supports them; separation of read-only roles from read-write roles; encryption at rest using platform-default mechanisms; audit logging of administrative database actions where the platform supports it.
G.6 Foreign Actor Defense Client portal authentication required for all data access; anonymous access disabled; failed-authentication rate limiting and lockout; rejection of unauthenticated database connections from public networks; monitoring of unusual access patterns; notification per Section 10.3 on suspected compromise.
G.7 Software Hygiene Timely application of security patches and dependency updates; periodic review of open-source components for known vulnerabilities.
G.8 Operational Logging Append-only operational logs for material System actions; retention for at least the term of this Agreement plus one year; logs accessible to Client through the client portal per Section 11; logs include authentication events, configuration changes, data-modifying agent runs, errors, and security-relevant events.
G.9 Backup & Recovery Backups per Section 11 written to Client-owned storage; backup integrity tested at least quarterly; documented restore procedure included in Schedule E.
G.10 Incident Response Notification within 72 hours of confirmed or reasonably suspected security incident per Section 10.3; post-incident report shared with Client within fourteen (14) days of remediation.
G.11 Personnel All personnel with access to Client Confidential Information bound by confidentiality obligations.
Schedule H

Disaster Scenarios and Mitigations

Reasonably foreseeable disaster scenarios and Service Provider's mitigation approach. Schedule H is descriptive of design intent, not a service-level agreement, except where explicitly stated.

# Scenario Mitigation Recovery target
1 Client Database corruption or data loss Restore from most recent automated backup (Section 11.1) to a fresh instance; replay any reproducible operations from Project Repositories RPO ≤ 24h; recovery time best-efforts
2 Single inference provider outage Automatic switchover to alternative inference provider via OpenRouter or equivalent abstraction Best-efforts continuity; intermittent agent run failures may occur during switchover
3 Multiple inference providers down simultaneously Force majeure per Section 17; agent runs paused; portal remains available for static data Subject to provider availability
4 Platform vendor outage (hosting, database, orchestration) Communication via portal or alternate channel; vendor-recommended remediation; failover where reasonably available Subject to vendor outage duration
5 Repository host outage Project Repositories mirrored on Client-owned backup destination; deployments may continue from local clones during outage Subject to vendor outage duration
6 Compromise of a Service Provider credential Immediate revocation; rotation of the affected credential; investigation per Section 10.3 Notification within 72h
7 Compromise of a Client-Provided credential Service Provider notifies Client; Client rotates; Service Provider receives new credential Continuity dependent on Client rotation timing
8 Catastrophic loss of multiple platforms simultaneously Restore from backups (Project Repositories from Git remote and Client-owned mirror; Client Database from Client-owned backup destination); rebuild on alternative platforms Best-efforts; multi-day recovery acknowledged
End of Draft v0

This document is to be reviewed by Service Provider's tax advisor (skattaráðgjafi) and Iceland-licensed legal counsel (lögmaður) before issuance to Client.