Non-Disclosure and Security Agreement

Version: v 3.0 (October 23, 2025)

This Non-Disclosure and Security Agreement (the “Agreement”) is entered into electronically by and between Terratra OÜ, an Estonian company (hereafter, “Terratra”), and Vendor (each a “Party,” together, the “Parties”).

Effective Date. The Effective Date is the date on which the Vendor electronically accepts this Agreement (for example, by ticking the acceptance box on the designated platform). Upon execution, an email copy of the executed Agreement is automatically sent to both Parties for their records.

Purpose. The Parties intend to explore or perform professional services and related workflows (the “Purpose”), including without limitation language and localization, translation, editing, proofreading, design and creative work, voice-over and dubbing, subtitling and closed captioning, transcription, interpretation, data collection and labeling, data analysis and analytics, project/program management, consulting, engineering, media production, and any other work mutually agreed by the Parties. In doing so, Terratra and its clients may disclose highly confidential materials.


1. Definitions

1.1 “Confidential Information” (“CI”). CI means any non-public information disclosed by a Party (“Disclosing Party”) to the other (“Receiving Party”) in any form, including oral, visual, or electronic. CI includes information marked confidential and also information that reasonably should be understood to be confidential given its nature or context of disclosure. Without limitation, CI includes: client identities; project names; source materials; prompts, outputs, annotations, QA feedback; translation memories (TMs), term bases, style guides; deliverables and work product; pricing, commercial terms, and financials; security and IT configurations; credentials, access tokens, and network details; and any information designated as confidential by Terratra’s clients. Derived data, metadata, and compilations based on CI are also CI. If there is reasonable doubt, information shall be treated as CI.

1.2 Client Materials. “Client Materials” means CI provided by or on behalf of Terratra’s clients, which may constitute trade secrets and may include Personal Data or Special-Category Data.

1.3 Personal Data. “Personal Data” has the meaning under applicable data-protection law (for example, GDPR, CCPA). “Special-Category Data” includes health, biometric, genetic, racial/ethnic, political, religious, and other sensitive attributes.

1.4 Trade Secrets. Information qualifying as trade secrets under applicable law (including Estonian law).

2. Confidentiality and Permitted Use

2.1 Need-to-Know Access. The Receiving Party shall use CI solely for the Purpose and disclose it only to personnel (including approved subcontractors) who have a strict need to know and are bound by written confidentiality obligations no less protective than this Agreement. The Receiving Party remains responsible for their compliance.

2.2 No Reverse Engineering or Mining. The Receiving Party shall not analyze CI to discover underlying processes or datasets, nor use CI to compile competitive intelligence or create derivative datasets except as required to perform the Purpose.

2.3 No AI/MT Without Approval. The Receiving Party shall not input CI (including Client Materials) into, or expose it to, public or third-party AI/ML or machine-translation systems (including for training, fine-tuning, or inference) without Terratra’s prior written approval and a signed addendum specifying safeguards, zero-retention assurances, and data-processing terms. Local, offline CAT tools may be used only with strict local storage and no vendor data harvesting or model training.

2.4 Cloud-Only Workflow; No Exfiltration. When Terratra provides a secured cloud/server environment, all access, processing, and storage of CI must occur exclusively within that environment. The Receiving Party shall not download, export, print, screenshot, or otherwise remove CI from the provided environment without Terratra’s prior written consent.

2.5 Remuneration Confidentiality. The Vendor’s remuneration, rates, pricing, discounts, and all commercial terms with Terratra are CI and shall not be disclosed to third parties except (i) to the Vendor’s professional advisers under confidentiality or (ii) as required by law, in which case the Vendor shall give prompt notice to Terratra (to the extent legally permitted).

3. Security Controls

3.1 Baseline Controls. The Receiving Party shall implement controls commensurate with the sensitivity of CI, including encrypted transit and storage, strong authentication and role-based access, endpoint protections, timely patching, least-privilege access and audit logging, and secure deletion on retirement of media or systems holding CI.

3.2 Anti-Malware/EDR. All endpoints used to access CI must run up-to-date anti-malware or endpoint detection and response (EDR) software with automatic signature/engine updates and real-time protection enabled. Disabling or bypassing such protections is prohibited.

3.3 Environment Restrictions. CI may not be stored on shared or personal devices lacking the controls in Section 3.1. Portable media must be encrypted. Public cloud services may be used only if the provider contractually commits to no secondary use, training, or analytics on CI, and offers encryption and access controls consistent with industry practice.

3.4 Subprocessors. Any subcontractor or subprocessor handling CI requires Terratra’s prior written consent and must be bound by obligations at least as protective as this Agreement, including security, confidentiality, and breach-notification terms.

4. Data Protection

4.1 Compliance. Each Party shall comply with applicable data-protection laws, including GDPR and, as applicable, CCPA. Where the Receiving Party processes Personal Data on behalf of Terratra or its clients, the Parties shall execute a data-processing addendum (DPA), which prevails in case of conflict with this Agreement.

4.2 Cross-Border Transfers. International transfers shall comply with applicable transfer mechanisms (for example, SCCs under GDPR).

4.3 Data Minimization and Retention. Collect and retain only what is necessary for the Purpose. Unless legally required, delete CI within thirty (30) days of completion of the Purpose or upon written request, and certify deletion upon request.

4.4 Breach Notice. The Receiving Party shall notify the Disclosing Party without undue delay and in any case within twenty-four (24) hours of discovering actual or suspected unauthorized access, use, or disclosure of CI, providing details, containment steps, and remediation plans, and shall cooperate fully.

5. Rights, Ownership, and Return/Destruction

5.1 Ownership. No license or right is granted in CI except as expressly stated. Each Party retains ownership of its CI. Client Materials remain the property of the relevant client; Terratra may enforce this Agreement to protect its clients as intended third-party beneficiaries.

5.2 Return/Destruction and Post-Project Purge. Upon request or termination of discussions, and in any case within seven (7) days after project completion and settlement of payment, the Receiving Party shall permanently purge all CI and Client Materials from all locations—online and offline—including active systems, shared drives, collaboration tools, caches, backups (to the extent technically feasible), temporary folders, and trash/recycle bins. The Receiving Party shall provide written certification of deletion upon request. Where retention is legally required, the Receiving Party shall (i) notify Terratra of the legal basis and retention period, (ii) segregate retained CI under continued protections, and (iii) delete promptly upon expiration of the legal hold.

5.3 Residuals. No residuals license is granted; the Receiving Party shall not rely on unaided memory to use CI after deletion/return.

6. Non-Solicitation and Non-Circumvention

6.1 Client Non-Circumvention. For three (3) years after the last disclosure of specific client identity by Terratra to Vendor, Vendor shall not directly solicit or contract with those identified Terratra clients for the same or substantially similar services without Terratra’s prior written consent. This does not restrict Vendor’s work with unrelated clients or via unrelated channels.

6.2 Non-Solicitation of Personnel. During the term and for twelve (12) months thereafter, neither Party shall directly solicit the other Party’s employees or core contractors involved in the Purpose, except through general public solicitations not specifically targeting such individuals.

7. Audit and Assurance

7.1 Verification. Upon seven (7) business days’ written notice, Terratra may reasonably verify compliance with this Agreement (for example, remote review of policies, control attestations, or third-party certifications such as ISO 27001/27701). Audits shall minimize disruption and protect the Receiving Party’s unrelated confidential information.

7.2 Attestations. On request, the Receiving Party shall provide written security and privacy attestations describing controls relevant to CI, including access lists and retention status.

8. Term, Injunctive Relief, and Liability

8.1 Term. This Agreement begins on the Effective Date and governs CI disclosed for the Purpose. Obligations for CI survive for the longer of (i) five (5) years after the later of termination of discussions or last disclosure, or (ii) for so long as such CI remains non-public and confidential under applicable law or contract. Obligations for Trade Secrets, Client Materials, and Personal Data continue for so long as they remain protected under applicable law or client contract, or are required by law, whichever is longer.

8.2 Equitable Relief. Unauthorized use or disclosure of CI may cause irreparable harm. The Disclosing Party (and for Client Materials, the relevant client and Terratra) may seek injunctive relief in addition to any other remedies.

8.3 Liability. The Vendor is fully responsible for, and shall indemnify and hold harmless Terratra and its clients against, all losses, costs, damages, fines, penalties, assessments, remediation, investigation, and reasonable attorneys’ fees arising from or related to Vendor’s (including its personnel’s and approved subcontractors’) breach of this Agreement, misuse of CI, security failures, data-protection violations, or non-circumvention breaches. To the maximum extent permitted by law, Terratra’s liability is limited to direct damages arising solely from its willful misconduct; Terratra shall have no liability for indirect, incidental, special, consequential, or punitive damages.

9. Miscellaneous

9.1 Governing Law; Forum. Estonian law governs this Agreement, excluding conflict-of-laws rules. Disputes shall be resolved in Tallinn, Estonia; the Parties consent to that venue, without prejudice to urgent injunctive relief in any competent court.

9.2 Electronic Execution. This Agreement is executed electronically. By ticking the acceptance box, the Vendor confirms it has read, understood, and accepted the terms on its own behalf. No further signature by Terratra is required for this Agreement to be effective. The electronic record (including acceptance logs, name, email, timestamp, IP address, and user-agent where available) is deemed an original and admissible as evidence. Upon the Vendor’s acceptance, an electronic copy of the executed Agreement will be emailed to both Parties.

9.3 Entire Agreement; Precedence. This Agreement is the entire agreement regarding CI for the Purpose. If a data-processing addendum (DPA) or project agreement conflicts with this Agreement for Personal Data or security controls, the DPA or project agreement prevails to the extent of conflict.

9.4 Severability and Assignment. Invalid terms are replaced with valid terms closest in intent; the remainder remains in force. Assignment is not permitted without prior written consent, except to a successor in interest that assumes all obligations.

9.5 No Waiver. Failure to enforce any provision is not a waiver.

9.6 Authority and Representation. Terratra OÜ is represented by Olga Stavrinides, Chief Operating Officer (COO) and a member of the board, who is duly authorized to implement and administer agreements of this nature on Terratra’s behalf.

ACCEPTANCE NOTICE: This Agreement is effective upon the Vendor’s electronic acceptance as described in Section 9.2. No handwritten or wet signatures are required.

© Terratra OÜ. This document may be reproduced for execution with vendors engaged by Terratra.