# Data Processing Addendum

## Version Information
- **Version number**: 4.1 (subprocessor update)
- **Publish date**: April 14th, 2026

## Parties
Ledgy AG, a stock corporation formed under the laws of Switzerland, with company number CHE-261.454.963 (“Ledgy”), and the customer (the “Customer”) (each a “Party” and together the “Parties”), hereby agree as follows:

## 1. Scope
### 1.1 Applicability
This data processing addendum (the “Addendum”) applies exclusively to the processing of personal data (the “Customer Personal Data”) by Ledgy on behalf of the Customer where such processing is subject to European Union (EU), United Kingdom (UK), or Swiss data privacy law. This Addendum, including its annexes, forms part of, and is subject to, the provisions of the agreement between the parties (the “Services Agreement”).

### 1.2 Definitions
- **EU Data Privacy Law**: Regulation (EU) 2016/679 (GDPR).
- **UK Data Privacy Law**: All laws relating to data protection in force from time to time in the UK.
- **Swiss Data Privacy Law**: The Revised Federal Data Protection Act.
- Collectively referred to as “Data Privacy Law”.

### 1.3 Terms Definitions
Terms such as “processing”, “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Sub-Processors” and “Data Breach” shall have the meaning ascribed to them in Data Privacy Law.

## 2. Binding Character of this Addendum
The Parties hereby agree to be bound by the provisions set forth in this Addendum in respect of their data protection obligations.

## 3. Details of Processing
### 3.1 Subject matter of processing
Equity management services via an online software application (the “Application”).
### 3.2 Duration of processing
For the duration of the Services Agreement until terminated.
### 3.3 Purpose of processing
Provision of the Services.
### 3.4 Categories of Personal Data
- **Equity Data**: Shareholder information, transaction history.
- **General Personal Data**: Name, surname, title, date of birth, contact information.
### 3.5 Categories of Data Subjects
Shareholders and natural persons who access and use the account (e.g., advisors).

## 4. Roles of the Parties
The Customer is the Controller, and Ledgy is the Processor.

## 5. Ledgy’s Obligations
Ledgy shall:
- Process Customer Personal Data on documented instructions from the Customer.
- Ensure personnel who access Customer Personal Data are committed to confidentiality.
- Maintain appropriate measures to protect Customer Personal Data.
- Assist the Customer in fulfilling obligations related to Data Subject rights.
- Delete personal data processed on behalf of the Customer after two years of inactivity.

## 6. The Customer’s Obligations
The Customer ensures:
- Instructions to process Customer Personal Data are compliant with Data Privacy Law.
- Customer Personal Data provided is accurate and updated when needed.
- Data Subjects have been notified about data storage periods.

## 7. Sub-processors
### 7.1 Authorisation
The Customer authorizes Ledgy to appoint Sub-Processors listed in Annex 2.
### 7.2 Responsibilities
Ledgy shall ensure agreements with Sub-Processors contain similar obligations.

## 8. Audit Rights
Ledgy shall maintain records of processing activities and provide access upon Customer request.

## 9. Personal Data Breach
In the event of a breach, Ledgy shall notify the Customer without undue delay.

## 10. International Transfers
Ledgy may transfer Customer Personal Data outside of the European Economic Area in compliance with applicable Data Privacy Law.

## 11. Data Subject Rights
Ledgy shall assist the Customer to respond to Data Subject requests and complaints.

## 12. Liability
Ledgy is not liable for losses due to Customer’s instructions contrary to Data Privacy Law.

## 13. Order of Precedence
This Addendum shall prevail over the Services Agreement in the event of conflict.

## 14. Survival
This Addendum shall survive the termination of the Services Agreement until Ledgy no longer processes Customer Personal Data.

## Annex 1 - Technical and Organisational Measures
### Organizational Security Measures
- **Security Management**: Ledgy oversees information security and has defined roles.
- **Risk Management**: Ongoing identification and management of IT-related risks.
### Incident Response
- Procedures for handling and reporting data breaches.
- **Business Continuity**: Controls for maintaining processing continuity.
### Human Resource Security
- **Policy Compliance**: Ensures employee understanding of data protection obligations.

### Technical Security Measures
- **Access Control**: Rights assigned based on role necessity and least privilege.
- **Data Encryption**: Encryption of stored data and secure transmission over the Internet.

### Annex 2 - List of Sub-Processors
| Name of Sub-Processor | Location of Servers | Purpose | Data Processed |
| --- | --- | --- | --- |
| Airwallex | Global | Payment information collection | Payment information |
| AWS | EU | Offsite backup | Stakeholders and transaction data |
| Google Cloud | Switzerland, EU | Hosting | Stakeholders and transaction data |
| Mailgun | EU | E-mail | Email address, content of emails |
| MongoDB Atlas | Switzerland | Database | Stakeholders and transaction data, uploaded documents |
