# Ghaym Data Processing Agreement

**Version 1.1 — 2026-09-03**

| | |
|---|---|
| Document | Ghaym Data Processing Agreement (dual-law) |
| Version | 1.1 |
| Issued | 2026-09-03 |

---

## 0. How this document is assembled

Two parts, because two laws apply to the same relationship:

- **Part A** — a Jordan-law processor agreement. Ghaym operates from Jordan, so Jordan's
  Personal Data Protection Law No. 24 of 2023 governs Ghaym's own processing regardless of
  where a customer sits.
- **Part B** — the Saudi annex, for customers subject to the Saudi PDPL. It is the official
  SDAIA **Second Template (Controller to Processor)** Standard Contractual Clauses, attached
  unmodified, with the appendices as the only fillable part.

Part B applies **in addition to** Part A, not instead of it, and only for a customer to whom
the Saudi PDPL applies. Clause 5 of the SCCs says they prevail over any other agreement
between the parties on conflict, so where Part A and Part B disagree, Part B wins for that
customer.

The SCC text is attached rather than retyped, because the clauses may not be edited. SCC
**Rule 5** provides:

> "If any party modifies the approved text (except the blank fields that are required to be
> filled in Standard Contractual Clauses), such modifications shall not be recognized by the
> Competent Authority and shall be deemed a violation of the provisions of the Law and
> Regulations."

Clause 2(A) permits amendment only "to select the appropriate template or to add or update
information in the appendix." So Part B **incorporates the official PDF by reference**,
records its SHA-256 so the exact issue is identifiable, and fills only what Rule 5 permits to
be filled:

```
Standard Contractual Clauses (English), SDAIA, version 1.0, September 2024
sha256 2de9606a64c45d2daa89047a84411cb782a045a5d00fcc240145754d558f7c64
1,587,993 bytes, 41 pp., Document Classification: Public
```

**Rule 11** lets SDAIA change the clauses at any time and issue transitional rules, which is
why the hash is recorded: this document is re-cut when the recorded hash stops matching, when
Ghaym's registered particulars change, when a sub-processor is added or removed, or when the
processing location moves.

Part A is written as ordinary processor terms in the shape every processor agreement takes —
roles, instructions, confidentiality, security, sub-processors, data subject rights, breach,
audit, deletion, transfers, term. **Every clause that states a legal duty cites the article of
Jordan's law it comes from.** Where Jordan's law does not supply a duty, the clause says it is
commercial rather than statutory.

---

## Part A — Data Processing Agreement (Jordan law)

**Parties.** `[Customer legal name]` ("the Controller") and `[Ghaym registered legal name]`
("the Processor").

### A.1 Definitions

Terms not defined here carry the meaning given in Jordan's Personal Data Protection Law No.
24 of 2023 ("the **Jordan PDPL**"). "Personal Data" means personal data of the Controller's
data subjects processed by the Processor under this agreement.

The Processor processes personal data for the purposes it was collected for and is therefore
exempted by **Article 24(A)(2)** of the Jordan PDPL from the licences and permits of Article
24(A)(1): "Entities that Process Data for the purposes that it was collected are exempted from
the licenses and permits stipulated in sub-section (1) of this paragraph."

### A.2 Roles

The Processor acts in **two capacities in the same relationship**:

| Data | Ghaym's role |
|---|---|
| Everything the Controller puts on the platform — its application data, its databases, its end users' personal data | **Processor.** The Controller decides what is collected and why; Ghaym runs infrastructure on the Controller's instruction |
| The Controller's own account data — staff names, email addresses, phone numbers, billing identity | **Controller.** Ghaym decides these purposes and means itself, to run the account and meet its own obligations |

Part B and this Part apply to the first row. The second row is governed by Ghaym's privacy
policy, not by this agreement.

**Not covered:** where the Controller is itself a processor for a third party and uses Ghaym
as a sub-processor. The applicable SCC template for that case is the **Third Template
(Processor to Processor)**, which this document does not include. Such a customer needs a
separate instrument.

### A.3 Instructions

The Processor processes Personal Data only on the Controller's documented instructions,
which are: this agreement, Schedule 1, and the Controller's own use of the platform's
features. If the Processor believes an instruction breaches the Jordan PDPL, it tells the
Controller and is not obliged to act on it until the Controller confirms.

*Basis: Jordan PDPL **Article 12(B)**, which forbids the processor to "exceed the specified
purpose and duration of the Processing". The purpose is the Controller's to specify, so a
clause binding the Processor to the Controller's documented instructions is the operational
form of that duty. **Article 12(A)** requires processing "in accordance with the requirements
and conditions stipulated in this law, as well as the regulations and instructions issued
pursuant to it": the regulations of the Council of Ministers under **Article 24** and the
instructions of the Personal Data Protection Council under **Article 8(B)**. The first
sentence of this clause is statutory in substance; the second, the duty to challenge an
unlawful instruction, is contractual.*

### A.4 Confidentiality

The Processor keeps Personal Data confidential and grants access only to personnel who need
it to perform the service and who are under a duty of confidentiality.

*Basis: Jordan PDPL Article 13, which is direct and short: "Data undergoing Processing is
considered confidential, and it is the responsibility of **the Controller and the Processor**
to maintain its confidentiality." This is a statutory duty on Ghaym itself, not a term the
Controller has to negotiate for.*

### A.4b Not enabling access

The Processor takes no action that would enable Personal Data, or the results of processing
it, to be accessed by anyone other than the Controller, the personnel described in §A.4, and
the sub-processors authorised under §A.6 — except in cases authorised by law.

Where the law authorises such access without compelling it, the Processor does not enable it
unless the Controller has agreed in writing. That is a **narrower commitment than Article 12(D)
requires**: it is not a restatement of the statutory exception.

*Basis: Jordan PDPL **Article 12(D)**, which requires the processor to "refrain from any action
that would enable the Data or Processing results to be accessed, except in cases authorised by
law." This is a separate duty from Article 13 confidentiality in §A.4: §A.4 concerns not
disclosing what the Processor holds, and 12(D) concerns not building or leaving in place the
means by which someone else could reach it. "Processing results" reaches beyond the Personal
Data as supplied, and this agreement reads it to include Ghaym's platform logs and the alerts
that leave the box (§A.6's list); the clause is written to that reading.*

### A.5 Security

The Processor applies the technical and organisational measures set out in **Schedule 2**,
which describes what runs.

*Basis: Jordan PDPL Article 8(A), under which the controller must take "necessary measures
to protect the Data under its custody and any Data received from any other person", and
Article 8(B), which requires "security, technical, and organisational measures". Article 14(E) then puts the same duty on the Processor **directly**: "The Controller,
Processor, and Recipient shall ensure the safety and security of the Data and provide
appropriate measures to detect and track any breach of its security and safety." So this
clause records a statutory obligation Ghaym already owes; it does not create one by
contract, and a Controller cannot waive it.*

### A.6 Sub-processors

The Controller authorises the Processor to engage the sub-processors named in **Schedule 3**.
A sub-processor is added to Schedule 3 **before** it enters the production path, and this
document is re-cut when it is.

The Processor imposes on each sub-processor obligations no less protective than these, and
remains liable to the Controller for their performance.

> **DamaMax.** DamaMax supplies the **virtual machines** amman-1 runs on and operates the
> hypervisor beneath them, in its own facility in Amman. A data processing agreement is in
> place between Ghaym and DamaMax. It is the row in Schedule 3.

> **Onward transfers out of Jordan.** Article 15(B) puts the duty to verify a foreign
> recipient's level of protection on the **Controller**, and for its own operational
> providers Ghaym is that controller. Ghaym verified each recipient's level of protection
> before the transfer to it began. §A.11 is where the article is worked through.

*Basis: Jordan PDPL Article 15(B), which puts a positive duty on the controller to verify
the protection level provided by a recipient outside Jordan before transferring. Article
14(B) separately requires the controller to "keep records documenting the Data that has been
transferred", which is what Schedule 3 and this document's dated revisions are for.*

### A.7 Data subject rights

The Processor assists the Controller in responding to a data subject exercising rights under
the Jordan PDPL. Article 4(B) is the list: awareness and access to the data held, and the
ability to obtain it (4(B)(1)); withdrawal of consent (4(B)(2)); correction, amendment,
addition or update (4(B)(3)); limiting processing to a specific scope (4(B)(4)); and erasure
or concealment (4(B)(5)). Article 10 is the separate duty that follows an erasure request —
the controller must erase or hide the data, on the data subject's request or the Unit's, in
the enumerated cases.

Where a data subject contacts the Processor directly about data processed for a Controller,
the Processor **does not answer** and forwards the request to the Controller. For a customer
under Part B, SCC Second Template §10(A) requires the Processor to notify the Controller of
such a request **within 48 hours** of receiving it, and bars it from responding without the
Controller's authorisation.

*Basis: Jordan PDPL Article 4(B) for the rights and Article 10 for erasure; SCC Second
Template §10(A) for Part B customers. Note Article 4(C): exercising these rights must not
entail financial or contractual consequences for the data subject, "without prejudice to the
rights of the controller" — so a fee or a service penalty for a rights request is not
available.*

### A.8 Personal data breach

On becoming aware of a personal data breach affecting Personal Data, the Processor contains
it and notifies the Controller without undue delay, giving what is known of the cause, the
measures taken, and a contact for follow-up.

The allocation is:

- Notifying **the Controller** is the Processor's duty, **within 24 hours** of the breach
  occurring or of the Processor becoming aware of it, whichever is earlier.
- Notifying **SDAIA**, or the Jordanian Unit, or the affected data subjects, is the
  **Controller's** duty. Jordan PDPL Article 20(A) opens "the Controller shall take the
  following actions", and sets the Controller's clocks: notification to affected data subjects
  within 24 hours of discovery of a serious breach, and notification to the Unit within 72
  hours.

*Basis: Jordan PDPL Article 20(A) for the Controller's duties; SCC Second Template §6(D) for
Part B customers. SCC Clause 12(A) sits under "Duration and Termination" and covers the
different case where the importer "is unable to fulfill its obligations under these Standard
Contractual Clauses", which it must report within 24 hours; that duty is stated in §A.12.*

### A.9 Audit and evidence

The Processor answers the Controller's reasonable enquiries about compliance with this
agreement and supplies the evidence it holds. For Part B customers, SCC Second Template §9(C)
goes further and gives the Controller a right of audit by itself or its representatives; that
right is not narrowed here, and Rule 4 would not permit it to be.

*Basis: **commercial, not statutory** — for Part A. Article 12 of Jordan's law sets out the
processor's duties in four paragraphs (A)–(D) and none of them is an audit or evidence duty,
so there is no article to cite here. Ghaym offers this clause because a controller cannot
discharge its own Article 8 security obligations over a processor it cannot ask questions of. For Part B customers the audit right
is statutory rather than offered, and its source is the SCC clause named above.*

### A.10 Deletion and return

On termination, or when the purpose is complete, the Processor deletes the Personal Data or
returns it at the Controller's election, and confirms deletion in writing. It documents the
deletion and gives the record to the Controller on request. Backup copies held under
Schedule 2 heading 7 are not deleted one by one: they expire in the ordinary rotation of the
backup set, and until then are used only to restore the service.

*Basis: Jordan PDPL Article 12(C), under which the processor shall "Erase the Data upon the
expiration of the Processing period, or transferring it back to the Controller" — quoted as
the source has it. The deletion-or-return election in this clause is that article, not a
commercial term. For Part B customers, SCC Second Template §5(A) governs destroy-or-return and
requires the Importer to notify the Exporter once it is done, but requires no record of it.

The written record in this clause is therefore offered rather than compelled by §5(A).*

> **Deletion timings.** Deleting a workspace deletes its data; its backup copies expire with
> the rotation of the backup set. Deployment logs — Schedule 2 heading 5 — live for as long as
> the service they belong to and are deleted with it: the log rows cascade from the
> deployment, the deployment cascades from the service.

### A.11 Transfers outside Jordan

The Processor does not transfer Personal Data to a recipient outside Jordan. The only
sub-processor engaged under §A.6 is in Jordan, and Schedule 3 names it.

*Basis: Jordan PDPL Article 15, which prohibits transfer to a person outside Jordan providing
lower protection than the law requires, outside six enumerated cases, and Article 15(B),
which requires the controller to verify that protection level first.*

> **Which transfers Article 15 reaches.** Personal Data under this agreement is stored
> and executed in amman-1, in Amman, on virtual machines supplied by DamaMax — inside Jordan,
> so Article 15 is not engaged by the hosting, and no sub-processor under §A.6 sits outside
> Jordan. The providers Ghaym operates with outside Jordan, named in Schedule 3, receive no
> Personal Data covered by this agreement. Two of them do hold personal data Ghaym is itself
> the controller of: the source-code host holds the Controller's own account identity and its
> repository grants (§A.2 row 2), and the fonts see the IP address and browser of whoever
> opens a Ghaym web page. Both are governed by the published privacy policy rather than by
> this agreement, so Ghaym owes Article 15(B) verification for them as controller of its own
> data rather than under this instrument. Ghaym verified the level of protection at each
> recipient outside Jordan before the transfer to it began.

### A.11b Registration in the Jordanian registry

Each party discharges its own registration duty under Jordan's law in respect of the data it
is controller of, and neither discharges the other's. The Processor is registered in the
registry of controllers, processors and data protection officers maintained under **Article
18(D)**, and keeps its entry current.

*Basis: Jordan PDPL **Article 18(D)**, which has the Unit establish "a registry that includes
records of Controllers, Processors, and Data Protection Officers … according to instructions
issued by the Council for this purpose", and the instructions issued under it —
تعليمات سجل مسؤولي ومعالجي ومراقبي حماية البيانات, gazetted at Official Gazette pp. 1197–1198.
The registry is open to controllers outside Jordan as well as inside, so being a foreign
counterparty does not remove the duty from a Controller either.*

### A.12 Term, termination and governing law

This agreement runs for as long as the Processor processes Personal Data for the Controller.
It is governed by and construed under the laws of the Hashemite Kingdom of Jordan, and the
competent civil courts of Amman, the Hashemite Kingdom of Jordan, have exclusive jurisdiction
over any dispute arising out of or in connection with it.

If the Processor becomes unable to fulfil its obligations under the SCCs in Part B, it tells
the Controller of that **within 24 hours** of becoming aware — whether or not a breach has
occurred. The Controller **shall then immediately cease transferring**; the Processor is given
**30 days, extendable once by the same period**, to prove it can comply, and if that expires
without proof the parties **shall agree to terminate** the contract.

*Basis: SCC Clause 12(A) and 12(B), which sit under "Duration and Termination" and are
therefore stated here rather than in §A.8. **The Controller's duty here is mandatory, not
elective**: 12(B) says the exporter "shall immediately cease the transfer", and termination is
likewise a bilateral act the clause obliges — "the two parties shall agree to terminate the
contract" — rather than something that happens by itself when the period runs out.*

> **The Jordan-law forum clause above reaches Part A only.** SCC Clause 8 provides that the
> Clauses "shall be governed by the applicable laws of the Kingdom of Saudi Arabia", that
> disputes "arising from the application of the provisions of these Clauses" fall to Saudi
> courts, and that the Importer "agrees to submit to the jurisdiction of the Kingdom of Saudi
> Arabia". Rule 4 forbids any term that conflicts with or narrows the Clauses, so for a Part B
> customer Clause 8 governs the matters Part B governs, and the clause above governs the rest.

> **This agreement takes no liability position.** There is no cap, no indemnity, no general
> exclusion and no insurance commitment in it. The only liability language in the instrument
> is one narrow disclaimer, attached to the termination in Clause 12(B).

### A.13 Language

This agreement is made in Arabic, and the Arabic text is the authoritative text. This English
version is a translation of it, and where the two differ the Arabic text governs. The Standard
Contractual Clauses in Part B are read in the official text issued by SDAIA and identified in
§0.

---

## Schedule 1 — Description of the processing

| | |
|---|---|
| **Subject matter** | Provision of the Ghaym Cloud platform: hosting, running and deploying the Controller's applications and databases |
| **Duration** | The term of the Controller's account, plus the time taken to delete or return the data under §A.10 |
| **Nature and purpose** | Storage, hosting, execution, transmission and deletion, solely to operate the service |
| **Categories of data subjects** | Whoever the Controller's application collects data about — determined by the Controller, unknown to Ghaym |
| **Categories of personal data** | Whatever the Controller stores — determined by the Controller, unknown to Ghaym |
| **Sensitive data** | Ghaym does not know whether the Controller stores sensitive data. See the note below |
| **Processing location** | amman-1 — Amman, Jordan. The virtual machines are supplied by DamaMax, which operates the hypervisor; Ghaym operates no facility and no hardware of its own |
| **Sub-processors** | As named in Schedule 3 |

> **On "unknown to Ghaym".** A general-purpose hosting platform does not inspect customer
> databases, so it cannot enumerate the categories, and SCC Appendix 2 fields 1, 2 and 3
> require them to be stated. **Appendix 2 is therefore completed by the Controller, not by
> Ghaym.**

---

## Schedule 2 — Security measures

Answered against SDAIA's eight Appendix 3 headings so that Part B and Part A cannot diverge.
SDAIA states its own bullet lists are "examples only, and the parties should ensure that the
description in this Appendix corresponds to the applicable facts relevant to the transfer."
They are therefore **not copied**. What follows is what runs.

| # | Heading | What Ghaym does |
|---|---|---|
| 1 | Controlling access to buildings and facilities | **Inherited from DamaMax**, which supplies the virtual machines the platform runs on and operates the hypervisor beneath them, in its own facility in Amman. A data processing agreement is in place between Ghaym and DamaMax |
| 2 | IT system access control | Administrative access runs over a private network rather than the public internet — a Tailscale overlay, a plain node join, no exit node, no route advertisement, OpenSSH remaining the only SSH daemon — and is limited to the people who operate the platform. **Public TCP/22 is closed.** Every administrative login raises an alert |
| 3 | Personal Data access control | Ghaym staff access is limited to the personnel who operate the platform. Deployment logs (heading 5) capture the customer's own application output and are queryable by those personnel |
| 4 | Personal Data disclosure control | Traffic is served over TLS. At rest, customer environment variables, secrets and deployment env snapshots are sealed with AES-256-GCM under a master key held by the platform |
| 5 | Input control | Platform actions are logged on the server (Loki/Prometheus/Grafana). Alerts leave the box to ntfy.sh naming the service and the fault only; log contents do not leave. **Everything a customer's running application writes to stdout and stderr is captured into its deployment log and stored for as long as the service it belongs to lasts**; deleting the service deletes it, by cascade. What lands there is decided by the customer's logging, so it can contain personal data of their users. The published privacy policy discloses this |
| 6 | Functionality control — separating controller and processor responsibilities | The split in §A.2 is the answer. It is stated in this agreement and in the published privacy policy |
| 7 | **Personal Data accessibility control** (availability) | Backups of the Controller's databases and volumes are taken and held in Jordan; no party other than those named in Schedule 3 holds a copy. The Controller may also export its data at any time |
| 8 | Personal Data segregation control | Customer workloads run in separate containers on shared infrastructure |

---

## Schedule 3 — Sub-processors

The sub-processors the Controller authorises under §A.6. **DamaMax is the only party that can
reach the Controller's Personal Data.**

| Sub-processor | Role | Location | Agreement |
|---|---|---|---|
| DamaMax | Supplies the virtual machines amman-1 runs on and operates the hypervisor beneath them, in its own facility in Amman | Amman, Jordan | A data processing agreement is in place between Ghaym and DamaMax |

**No other party receives the Controller's Personal Data.** The remaining providers Ghaym
operates with outside Jordan are not sub-processors under this agreement. The first four see
operational metadata only; the fonts see personal data, but it is **Ghaym's own visitors', not
the Controller's**, and Ghaym is its controller under the published privacy policy rather than
under this instrument.

| Provider | Location | What it sees | Personal data of the Controller? |
|---|---|---|---|
| GitHub (source-code host) | United States | The account identity and the repository grants described in §A.2 row 2, which this agreement does not govern | No |
| Cloudflare (DNS) | United States | DNS query metadata, and the Service's traffic when it is enabled against an attack | No |
| Let's Encrypt (certificate issuance) | United States | Domain names, which are published in the Certificate Transparency logs | No |
| Tailscale (private administration network) | United States | Staff device metadata. The sessions are end-to-end encrypted | No |
| Google (fonts) | United States | The IP address and browser of whoever opens a Ghaym web page — personal data of that visitor | No. Ghaym is the controller of it, under the privacy policy |

Analytics run on Ghaym's own servers, in Jordan. Payment is CliQ or bank transfer, settled
outside the platform.

---

## Part B — Saudi annex: SDAIA Standard Contractual Clauses

**Applies to:** a Controller to whom the Saudi Personal Data Protection Law applies, where
personal data is transferred to Ghaym outside the Kingdom.

**Template:** Second Template — **Controller to Processor**. The Controller is the Personal
Data Exporter; Ghaym is the Personal Data Importer. The other three templates are deleted, as
the document requires: parties "must identify the template that applies to the relevant
transfers according to the nature of their roles and delete those that do not apply."

**Clause text:** the official SDAIA Standard Contractual Clauses, version 1.0 of September
2024, incorporated in full and **unmodified**, identified by the SHA-256 recorded in §0 and
attached to the executed agreement as issued. Not reproduced here — see §0 for why.

### B.0 What this annex incorporates, and who completes what

This annex incorporates the SDAIA Standard Contractual Clauses — Second Template, Controller
to Processor — **unmodified**, identified by the SHA-256 recorded in §0, and attaches them to
the executed agreement.

Its three appendices are the only fillable part, and they are divided as follows:

- **Appendix 1 (Parties)** is completed on signature: each party transcribes its registered
  legal name, registered address, contact and authorised signatory.
- **Appendix 2 (Description of the transferred personal data)** fields 1 to 3 are **completed
  by the Controller**, because Ghaym does not inspect customer data and cannot enumerate
  categories it has never seen. Fields 4 and 5 are filled below.
- **Appendix 3 (Security measures)** is **Schedule 2** above, complete.

Executing these Clauses is one of the Transfer Regulation's conditions for the transfer. The
Controller's own risk assessment is the other.

**The transfer risk assessment is the Controller's to make, and this annex does not make it.**
Transfer Regulation Article 7(1) provides that "the controller shall conduct a risk assessment
before transferring or disclosing personal data to a party outside the Kingdom" in the cases
it lists, and Article 7(2) sets out the **six** elements that assessment must contain: (A) the
purpose and legal basis; (B) the nature of the transfer, including the processing activities
and their geographical scope; (C) the safeguards applied and whether they are adequate to a
level of protection not less than the Law requires; (D) the measures limiting the transfer to
the minimum data needed, in the cases not exempted by Article 29(2)(c) of the Law; (E) the
potential material or moral effects of the transfer and the likelihood of their occurrence;
and (F) the measures that will prevent those risks to data subjects or mitigate their effects
if they occur. SDAIA's Risk Assessment Guideline is the method.

Ghaym is the importer and does not discharge that duty for the Controller.

### B.1 Appendix 1 — Parties

| Field | Personal Data Exporter | Personal Data Importer |
|---|---|---|
| Name | `[Customer legal name]` | `[Ghaym registered legal name]` |
| Address | `[Customer registered address]` | `[Ghaym registered address]` |
| Contact information | `[Customer data-protection contact]` | `info@ghaym.me` |
| Signature | `[Customer signature]` | `[Signature of Ghaym's authorised signatory]` |
| Date | `[Date of execution]` | `[Date of issue]` |
| Role | **Controller** | **Processor** |

The appendix is headed, in SDAIA's own text, `[Note: The data in this appendix is updated for
all Phases]` — it is a living record, not a one-time fill, and Clause 7 uses this same
appendix as the mechanism by which a new party accedes.

### B.2 Appendix 2 — Description of the transferred personal data

**Fields 1 to 3 are completed by the Controller.** Ghaym does not inspect customer data and
does not know what the Controller stores. See the note under Schedule 1.

| # | Field | Value |
|---|---|---|
| 1 | Categories of data subjects whose personal data is transferred | `[Controller to complete]` |
| 2 | Categories of transferred personal data | `[Controller to complete]` |
| 3 | Categories of transferred sensitive data, if any, and the applicable restrictions and safeguards | `[Controller to complete.` If any, SCC Second Template §7 puts a duty on the **Exporter** to ensure the Importer adopts additional protection, so this field is not one Ghaym can answer alone`]` |
| 4 | Purpose of transfer | Provision of the Ghaym Cloud hosting platform, as described in Schedule 1 |
| 5 | Retention period / criteria | For the term of the account, then deleted per §A.10 |

> Field 3 is for sensitive data, for example health, biometric and credit data. The SCC text names purpose limitation,
> access restrictions, record-keeping of access, restrictions on subsequent transfers, and
> additional organisational, technical and regulatory measures as the safeguards to be
> specified for it.

### B.3 Appendix 3 — Security measures

As **Schedule 2** above, which answers SDAIA's eight example headings against what runs.
Stated once and referenced, so Part A and Part B cannot drift apart.
