Data Processing Addendum version 4

Data Processing Addendum

Version number: 4.0

Publish date: June 17th, 2025

Ledgy AG, a stock corporation formed under the laws of Switzerland, with company number CHE-261.454.963 (“Ledgy”), and the customer (the “Customer”) (each a “Party” and together the “Parties”), hereby agree as follows:

1. Scope

1.1 This data processing addendum (the “Addendum”) applies exclusively to the processing of personal data (the “Customer Personal Data”) by Ledgy on behalf of the Customer where such processing is subject to European Union (EU), United Kingdom (UK), or Swiss data privacy law. This Addendum, including its annexes, forms part of, and is subject to, the provisions of the agreement between the parties (the “Services Agreement”) in respect of the performance of services (the “Services”) by Ledgy to the Customer that include the processing of such Customer Personal Data.

1.2 The term “EU Data Privacy Law” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, including any future revision thereof, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR). The term “UK Data Privacy Law” means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the GDPR to the extent that it forms part of the United Kingdom’s local law as a result of Section 3 of the European Union (Withdrawal Act) 2018 and the Data Protection Act 2018. The term “Swiss Data Privacy Law” means the Revised Federal Data Protection Act, including any future revision thereof. EU Data Privacy Law, UK Data Privacy Law and Swiss Data Privacy Law are collectively referred to as “Data Privacy Law”.

1.3 Terms such as “processing”, “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Sub-Processors” and “Data Breach” shall have the meaning ascribed to them in Data Privacy Law, as applicable to the processing.

2. Binding Character of this Addendum

The Parties hereby agree to be bound by the provisions and obligations set forth in this Addendum in respect of all their data protection obligations and agree that any data protection and data processing obligations as agreed to previously amongst the Parties shall be deleted and repealed in its entirety and be replaced with this Addendum.

3. Details of Processing

The processing carried out by Ledgy will be as follows:

3.1 Subject matter of processing

Equity management services by means of an online software application (the “Application”) and the fulfilment of contractual obligations under the Services Agreement and this Addendum.

3.2 Duration of processing

For the duration of the Services Agreement until terminated or once processing by Ledgy of any Customer Personal Data is no longer required for the performance of its relevant obligations under the Services Agreement or the Addendum.

3.3 Purpose of processing

The provision of the Services.

3.4 Categories of Personal Data

3.5 Categories of Data Subjects

Shareholders and any other natural persons who access and use your account (e.g., advisors).

4. Roles of the Parties

The Customer and Ledgy hereby agree that for the purposes of this Addendum, the Customer shall be the Controller and Ledgy shall be the Processor.

5. Ledgy’s obligations

Ledgy, acting as Processor, shall:

5.1 only process Customer Personal Data on documented instructions from the Customer, unless required to do otherwise by applicable laws (provided that Ledgy first informs the Customer of that legal requirement before processing, unless that law prohibits this on important grounds of public interest). The Services Agreement, this Addendum along with the Customer's use of the Services constitute the Customer's documented instructions to Ledgy for the purpose of providing the Services. Ledgy shall immediately inform the Customer if instructions given by the Customer, in the opinion of Ledgy, contravene Data Privacy Law.

5.2 ensure that all personnel who have access to Customer Personal Data have committed themselves to appropriate obligations of confidentiality and only involve personnel in processing Customer Personal Data who have had appropriate training on the care and handling of Personal Data;

5.3 maintain appropriate technical and organizational measures to protect the Customer Personal Data. The Parties acknowledge that security requirements are constantly changing and that effective security requires frequent evaluation and regular improvements of outdated security measures. Ledgy will, therefore, evaluate the measures on an ongoing basis and will tighten, supplement and improve these measures as it deems necessary or appropriate in its sole discretion. An overview of the current technical and organizational measures can be found on Annex 1 of this Addendum;

5.4 assist the Customer, to the extent possible, to fulfill the Customer’s obligations in responding to requests for exercising of Data Subject rights set out in the applicable Data Privacy Law and to notify the Customer without unreasonable delay if Ledgy receives a request from a Data Subject to exercise the Data Subject’s privacy rights under applicable Data Protection Laws;

5.5 assist the Customer in complying with Article 35 (Data protection impact assessment) and Article 36 (Prior consultation) of the GDPR (or the respective definitions in the Swiss and UK Data Privacy Law) in respect of any new type of processing proposed, in accordance with Data Privacy Law.

5.6 deal promptly and properly with all reasonable inquiries from the Customer that relate to the processing under this Addendum.

5.7 In case of two years of inactivity of a user account, Ledgy shall delete all personal data processed on behalf of the Customer and certify to the data controller that it has done so and delete existing copies unless applicable law requires storage of the personal data.

6. The Customer’s obligations

The Customer, acting as the Controller, hereby warrants and represents:

6.1 that its instructions to Ledgy to process the Customer Personal Data will not breach Data Privacy Law, especially in regards to its lawfulness and the existence of legal basis for the data processing;

6.2 that Customer Personal Data provided to Ledgy is accurate and will be updated to ensure continued accuracy as and when required;

6.3 that it has notified Data Subjects of any applicable period for which Customer Personal Data or any element of Customer Personal Data will be stored by Ledgy;

6.4 that the Customer has the right to provide Customer Personal Data to Ledgy and has provided Data Subjects with all necessary information and data protection notices on or in connection with the collection of such Customer Personal Data from data subjects including, but not limited to, the supply of Customer Personal Data to Ledgy and details of the purposes for which such Customer Personal Data will be processed by Ledgy including, if applicable, as set out in Ledgy’s retention policy;

6.5 The Customer further warrants and represents:

6.5.1 that the Customer will not provide Ledgy with nor request Ledgy to process the types and categories of Personal Data listed, defined, or referenced to in Articles 8–10 of the GDPR or respective definitions in the UK and the Swiss Data Privacy Law, and

6.5.2 that the Customer will not provide Ledgy with nor pass to Ledgy personal data for which Ledgy has no knowledge of, is unaware of, or which is not explicitly provided for under this Addendum, and that where applicable, the Customer will not enter any personal data into free text fields embedded in relevant Ledgy products and/or Services and will not incorporate any personal data outside of the scope of Personal Data as contemplated in the Services Agreement and this Addendum into any attachments that are to be uploaded into Ledgy’s Application;

6.6 that the Customer shall, and shall procure its employees, contractors, and/or agents to keep the login credentials used to access to the Services secure and shall be liable for the access to the Services through such login credentials. The Customer further shall promptly notify Ledgy of any unauthorized use of any login credentials, or other breaches of security, including loss, theft or unauthorized disclosure of login credentials.

7. Sub-processors

7.1 The Customer hereby provides its prior, general authorisation for Ledgy to appoint the Sub-Processors listed in Annex 2 to process the Customer Personal Data in connection with the provision of the Services.

7.2  Ledgy shall:

7.2.1 enter into an agreement with each Sub-Processor containing obligations which are materially similar to those set out in this Addendum to the extent applicable to the nature of the services provided by such Sub-Processor; and

7.2.2 remain responsible for the acts and omissions of any such Sub-Processor as if they were the acts and omissions of Ledgy.

7.3 A list of Ledgy’s current Sub-Processors is set out at Annex 2. The Customer may request an up-to-date list of Sub-Processors at any time.

7.4 Ledgy will notify the Customer prior to transferring any Customer Personal Data to a new Sub-Processor. The Customer will notify Ledgy in writing within 30 days after being notified of such new Sub-Processor if it objects to the processing of its Customer Personal Data by the new Sub-Processor. In such event the parties will, acting reasonably, try to come to an agreement over the transfer of the Customer Personal Data to the applicable Sub-Processor. Where agreement is not possible the Customer shall be entitled to terminate the Services Agreement.

8. Audit Rights

8.1 Ledgy shall maintain complete, accurate and up to date written records of all categories of processing activities carried out on behalf of the Customer.

8.2 Such records shall include all information necessary to demonstrate Ledgy’s compliance with this Addendum. Ledgy shall make copies of such records referred to at clause 8.1 available to the Customer promptly on request.

8.3 Ledgy shall promptly make available to the Customer such information as is required to demonstrate Ledgy’s compliance with its obligations under the Data Privacy Law. Ledgy shall further permit the Customer or an accredited third-party auditor to conduct an audit to confirm such compliance. Such audit shall take place during Ledgy’s regular hours of business, not more than once in any 12 month period, and on not less than 8 weeks prior written notice. The Customer and its auditors (if any) shall enter into confidentiality agreements with Ledgy and shall comply with all Ledgy’s reasonable requirements to minimise disruption to Ledgy’s business. Any audit and request for information shall be limited to information necessary for the purposes of this Addendum and shall give due regard to Ledgy’s confidentiality obligations and legitimate interest to protect business secrets.

9. Personal Data Breach

9.1 In the event of a personal data breach concerning data processed by Ledgy, it shall notify the Customer without undue delay after having become aware of the breach. Such notification shall contain the details of a contact point where more information concerning the personal data breach can be obtained, a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and data records concerned), its likely consequences and the measures taken or proposed to be taken to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all information at the same time, the initial notification shall contain the information then available and further information shall be provided as it becomes available without undue delay.

9.2 Ledgy shall cooperate in good faith with and assist the Customer in any way necessary to enable the Customer to notify, where relevant, the competent data protection authority and the affected data subjects, taking into account the nature of processing and the information available to Ledgy.

10. International Transfers

Ledgy may transfer Customer Personal Data outside of the European Economic Area, United Kingdom or Switzerland as required to process the Customer Personal Data for the purpose under this Addendum, provided that Ledgy shall ensure that all such transfers are made in accordance with applicable Data Privacy Law, including by way of entering into standard contractual clauses adopted by the EU Commission (where the EU GDPR applies to the transfer) together with any applicable additional clauses required for transfers out of the United Kingdom or Switzerland, as applicable.

11. Data Subject Rights

Ledgy shall:

a) promptly notify the Customer about any request received directly from the data subject. It shall not respond to that request itself, unless and until it has been authorized to do so by the Customer.

b) reasonably assist the Customer in fulfilling its obligations to respond to data subjects’ requests for the exercise of their rights in accordance with applicable Data Privacy Law.

c) reasonably assist the Customer in case a data subject has lodged a complaint to the competent supervisory authority that concerns Customer Personal Data processed on the basis of this Addendum.

12. Liability

The Customer acknowledges that Ledgy is reliant on the Customer for instructions as to the extent to which Ledgy is entitled to use and process the Customer Personal Data. Consequently, Ledgy will not be liable for losses (including indirect losses, loss or corruption of data, loss of reputation, goodwill and profits), actions, proceedings and liabilities of whatsoever nature incurred by Ledgy or for which Ledgy may become liable due to any claim brought by a Data Subject or Supervisory Authority arising from the Customer’s instructions or use of the Services or Application in breach of the Data Privacy Law.

13. Order of Precedence

‍To the extent of any conflict between this Addendum and any parts of the Services Agreement, this Addendum shall prevail, govern, and supersede.

14. Survival

This Addendum and the obligations hereunder shall survive the termination or expiry of the Services Agreement however effected or arising, and shall continue until Ledgy no longer processes any Customer Personal Data. The Customer Personal Data will be returned to the Customer and deleted by Ledgy in accordance with the Services Agreement.

Annex 1

Annex 1 - Technical and Organisational Measures

This annex to the Data Processing Addendum outlines the technical and organizational measures implemented by Ledgy AG (“Ledgy”, "Processor" or the “data processor”) in compliance with its data protection obligations as a data processor.

Organizational Security Measures

Security Management

Incident Response and Business Continuity

Human Resource Security

Technical Security Measures

Access Control and Authentication

Logging and Monitoring

Data Protection and Security

Secure System Architecture

Application and System Lifecycle

Physical and Environmental Security

Annex 2 List of Sub-Processors

Name of sub-processor Location of servers Purpose Data processed
Google Cloud Zurich, Switzerland (Google) Hosting, workspace Stakeholders and transaction data, uploaded documents
Mailgun Frankfurt, Germany (AWS) E-mail Email address, content of the emails
MongoDB atlas Zurich, Switzerland (Google) Database Stakeholders and transaction data, uploaded documents
Skribble (if applicable) Zurich, Switzerland Electronic signatures Documents signed with AES or QES
Temporal Cloud Frankfurt, Germany (AWS) Monitoring workflows in the application E-mail address
Microsoft Office 365 Zurich, Switzerland Assisted onboarding Stakeholders and transaction data
Merge API Inc (if applicable) Stockholm, Sweden HRIS integration Employee identity information, organisational data, employment details, compensation data
AWS Dublin, Ireland Offsite backup Stakeholders and transaction data