Data Processing Addendum version 4.1

Data Processing Addendum

Version Information

Parties

Ledgy AG, a stock corporation formed under the laws of Switzerland, with company number CHE-261.454.963 (“Ledgy”), and the customer (the “Customer”) (each a “Party” and together the “Parties”), hereby agree as follows:

1. Scope

1.1 Applicability

This data processing addendum (the “Addendum”) applies exclusively to the processing of personal data (the “Customer Personal Data”) by Ledgy on behalf of the Customer where such processing is subject to European Union (EU), United Kingdom (UK), or Swiss data privacy law. This Addendum, including its annexes, forms part of, and is subject to, the provisions of the agreement between the parties (the “Services Agreement”).

1.2 Definitions

1.3 Terms Definitions

Terms such as “processing”, “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Sub-Processors” and “Data Breach” shall have the meaning ascribed to them in Data Privacy Law.

2. Binding Character of this Addendum

The Parties hereby agree to be bound by the provisions set forth in this Addendum in respect of their data protection obligations.

3. Details of Processing

3.1 Subject matter of processing

Equity management services via an online software application (the “Application”).

3.2 Duration of processing

For the duration of the Services Agreement until terminated.

3.3 Purpose of processing

Provision of the Services.

3.4 Categories of Personal Data

3.5 Categories of Data Subjects

Shareholders and natural persons who access and use the account (e.g., advisors).

4. Roles of the Parties

The Customer is the Controller, and Ledgy is the Processor.

5. Ledgy’s Obligations

Ledgy shall:

6. The Customer’s Obligations

The Customer ensures:

7. Sub-processors

7.1 Authorisation

The Customer authorizes Ledgy to appoint Sub-Processors listed in Annex 2.

7.2 Responsibilities

Ledgy shall ensure agreements with Sub-Processors contain similar obligations.

8. Audit Rights

Ledgy shall maintain records of processing activities and provide access upon Customer request.

9. Personal Data Breach

In the event of a breach, Ledgy shall notify the Customer without undue delay.

10. International Transfers

Ledgy may transfer Customer Personal Data outside of the European Economic Area in compliance with applicable Data Privacy Law.

11. Data Subject Rights

Ledgy shall assist the Customer to respond to Data Subject requests and complaints.

12. Liability

Ledgy is not liable for losses due to Customer’s instructions contrary to Data Privacy Law.

13. Order of Precedence

This Addendum shall prevail over the Services Agreement in the event of conflict.

14. Survival

This Addendum shall survive the termination of the Services Agreement until Ledgy no longer processes Customer Personal Data.

Annex 1 - Technical and Organisational Measures

Organizational Security Measures

Incident Response

Human Resource Security

Technical Security Measures

Annex 2 - List of Sub-Processors

Name of Sub-Processor Location of Servers Purpose Data Processed
Airwallex Global Payment information collection Payment information
AWS EU Offsite backup Stakeholders and transaction data
Google Cloud Switzerland, EU Hosting Stakeholders and transaction data
Mailgun EU E-mail Email address, content of emails
MongoDB Atlas Switzerland Database Stakeholders and transaction data, uploaded documents