Announcement: We’re excited to share that we’ve raised our next investment round, led by People Ventures and EIFO. Read about it here.

Security Annex

KLAAY SECURITY ANNEX
Version 1.1 (September 22, 2026). Forms part of the Klaay Data Processing Agreement

Defined terms not otherwise defined herein shall have the means ascribed to them in the Data Processing Agreement (“DPA.”) In case of a conflict between this Security Annex and the DPA, the DPA shall prevail.

1. Security Policy. Klaay maintains a company-wide information security management system and control program that includes written security policies, standards and procedures based upon SOC2 (collectively, the “Klaay Information Security Policy”). The Klaay Information Security Policy requires adherence to the following security principles (individually and collectively “Security Principle(s)”):

1.1 the identification and assessment of reasonably foreseeable internal and external risks to the security, confidentiality, integrity, and availability of Personal Data to the extent that such Customer Data is provided to Klaay and maintained or processed by Klaay during its provision of Services by utilizing key operations and security practices such as:

(1) Secure software development practices;

(2) Secure operating procedures and vulnerability management;

(3) Ongoing employee training;

(4) Controlling physical and electronic access to Personal Data, and

(5) Means for detecting and preventing intrusions and security system failures on critical systems.

1.2 that Klaay follow the principle of least privilege access, allowing only active Klaay employees and contractors access to records containing Personal Data and limits access to those persons who are reasonably required to know such information in order to accomplish a valid business purpose or to comply with record retention regulations;

1.3 that Personal Data is secured appropriately commensurate to the nature of Personal Data using commercially available and industry accepted controls and precautionary measures;

1.4 that commercially reasonable standards are followed with respect to strong change-control procedures and technical controls that enforce segregation of duties, minimum necessary dataset, and access controls;

1.5 monitoring of operations and maintaining procedures to ensure that security policies are operating in a manner reasonably calculated to prevent unauthorized access to or unauthorized use of Personal Data, and continuously improving information safeguards as necessary to mitigate risks;

1.6 a security patch and vulnerability management process based on accepted industry standard practices and protocols, including, monitoring threats, and responding to vulnerabilities reported by third parties; and

1.7 a security incident response and disaster recovery planning, including documentation of responsive actions taken in connection with any security incident related to Personal Data.

2. Security Practices and Processes

2.1 Customers are responsible for their own legal and regulatory compliance in its use of any Subscription Services and shall make Klaay aware of any Customer Data processed, stored, or transmitted through the Services for which regulations other than those set forth in this Annex apply. If, while providing Services, Klaay agrees in writing to process such Customer Data and Customer has subscribed to any applicable Services, Klaay shall process it only as permitted under this Agreement and in compliance with the DPA and applicable data protection legislation to which Klaay is subject as a service provider. If Klaay agrees to receive Customer Data from Customer, Klaay will manage and/or process such Customer Data pursuant to the security requirements, obligations, specifications and event reporting procedures as set forth in this Annex, the DPA, and the Agreement, and any amendments thereto.

2.2 Affiliates will comply with: (i) secure software development practices consistent with industry accepted standards and practices, and (ii) industry best practices on privacy and security.

2.3 Klaay Affiliates restrict access to Personal Data and systems by users, applications and other systems. These controls include (i) controls to systems and data, limited to properly authenticated and authorized individuals based on principles of least privilege and need-to-know; and (ii) physical access controls, as described below. Klaay will limit access to Personal Data to the minimum necessary dataset required to accomplish the intended business purpose or use. Klaay Affiliates facilities and/or any Sub-processor facilities that process Personal Data will be housed in secure areas and protected by perimeter security such as barrier access controls (e.g., electronic locks, access badges, and video surveillance) that provide a physically secure environment.

2.4 Klaay Affiliates log access to controlled systems and records, including successful and failed system access attempts, and restricts, and restricts the connection times of users. Klaay Affiliates will use unique logins on all network equipment, whenever commercially reasonable.

2.5 Klaay Affiliates maintain processes to identify and deploy security patches in a timely manner. Unless otherwise expressly agreed in writing, “timely” means that Klaay Affiliates will introduce a fix or patch as soon as commercially reasonable after Klaay Affiliates become aware of the security problem or availability of a fix or patch.

3. Patch and Vulnerability Management.

3.1 Klaay Affiliates follow commercially reasonable best practices for patch management, criticality ranking and patching time frame requirements for all Klaay-operated systems, switches, routers, appliances, servers, and workstation PC’s, as applicable.

3.2 Where feasible, Klaay Affiliates ensure that trusted, commercially available anti-virus software is installed, enabled, and kept current on Klaay servers and systems used in accessing, processing, transmitting, or storing Personal Data.

3.3 Klaay Affiliates maintain trusted, current, commercially available anti-malware protection capabilities on Klaay devices, particularly those used for accessing, processing, transmitting, or storing Personal Data.

3.4 Klaay Affiliates maintain a vulnerability management solution for devices connected to Klaay’s LAN. Such solution is designed to regularly assess Klaay’s network for known vulnerabilities.

4. Security Monitoring

4.1 Klaay Affiliates have a designated security team which monitors Klaay’s control environment which is designed to prevent unauthorized access to or modification of Personal Data. Klaay Affiliates regularly monitor controls of critical systems, network and procedures to validate proper implementation and effectiveness in addressing the threats, vulnerabilities and risks identified. This monitoring is variable by the criticality, exposure, and the system's assets and may include: (i) internal risk assessments; (ii) validation of multi-factor authentication for select environments; (iii) third party compliance, including hosting services and third party components; and (iv) assessing changes affecting systems processing authentications, authorizations, and auditing.

4.2 Klaay Affiliates perform periodic vulnerability assessments on Klaay applications and systems. Penetration tests are performed either by Klaay Affiliates or by an established, reputable independent third party.

5. Security of Data Processing. Klaay Affiliates have implemented and will maintain technical and organizational measures inclusive of administrative, technical and physical safeguards to ensure a level of security appropriate to the risk of the data processing for the Services and Klaay Customer Services as described in this Klaay Security Annex (the “Security Measures”). These Security Measures may be changed by Klaay Affiliates from time to time during the Term of the Agreement in order to take into account advancements in available security technologies. However, Klaay Affiliates may not materially decrease the overall security of the Services during the Term of the Agreement.

The Security Measures may include, but will not be limited to, the following measures for ensuring the ongoing confidentiality, integrity, and availability of Personal Data in order to prevent unauthorized access, use, modification or disclosure of Personal Data:

5.1 Background Checks. Performance of background checks on all personnel, as well as execution of non-disclosure commitments prior to employment and acknowledgment of professional behavior in the workplace documents, which includes anti-harassment and business ethics;

5.2 Training. Security and privacy awareness training, inclusive of acknowledgment and agreement to abide by organizational security policies, for all personnel upon hire and annually thereafter;

5.3 Personal Data. Pseudonymisation or encryption of Personal Data in transit and at rest utilizing industry-standard mechanisms for certain Klaay Services;

A process for regularly testing, assessing and evaluating the effectiveness of administrative, technical and physical safeguards for ensuring the security of the processing, transmission or storage of Personal Data through external and internal audits as further described below;

Preventing access, use, modification or disclosure of Personal Data except by authorized Klaay personnel (1) to provide the Services and Klaay Customer Services, and prevent or address service or technical problems, (2) as compelled by law, or (3) as an Klaay Affiliate expressly permits in writing.

5.4 Availability. The ability to restore the availability and access to Personal Data in a timely manner in the event of an incident impacting the availability of Personal Data by maintaining a backup solution for disaster recovery purposes;

5.5 Logging and Monitoring. Logging and monitoring of security logs via a Security Incident Event Management (“SIEM”) system and alerting to a dedicated Incident Response team upon the detection of suspicious system and/or user behaviors;

5.6 Vulnerability Triaging. Processes and tooling for regularly identifying, assessing and triaging vulnerabilities based on industry-standard guidelines;

5.7 Policies. Maintenance of a comprehensive set of security and privacy policies, procedures and plans that are reviewed on at least an annual basis and provide guidance to the organization regarding security and privacy practices; and,

5.8 Subprocessors. Processes for evaluating prospective and existing Subprocessors to ensure that they have the ability and commit to appropriate administrative, technical and physical measures to ensure the ongoing confidentiality, integrity and availability of Personal Data.

By implementing the Security Measures detailed above, Klaay Affiliates take into account the risks that are related to data processing, in particular the ones resulting from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored or otherwise processed.

6. Secure Data Transmissions. Any Personal Data that Klaay transmits over a public communications network will be protected during transmission by using, or making available, industry accepted standards such as TLS, SSH and VPNs.

7. Data and Media Disposal. Klaay Affiliates maintain procedures that align with industry standards, such as NIST SP 800-88, regarding the disposal of both tangible property and electronic files containing Personal Data, taking into account available technology so that Personal Data cannot be reconstructed and read.

8. Backup and Retention. Klaay Affiliates will backup systems to ensure adequate recovery capabilities for the applicable Services. Back-ups will be appropriately protected to ensure only authorized individuals are able to access the Personal Data, including but not limited to encryption of data stored off-site in electronic media and appropriate classification and protection of hard copy records, as applicable. If not separately backed up, Klaay will secure any files containing Personal Data against unauthorized access.

9. Business Continuity and Disaster Recovery. Klaay Affiliates maintain business continuity and disaster recovery planning processes to establish and maintain plans and procedures for the continuity, recovery and operation of information systems, processes and facilities that could impact the availability of Personal Data (“BC/DR Plans”). These BC/DR Plans include processes for responding to emergencies (e.g., natural disasters such as fire, earthquakes, or hurricanes, or other disasters such as sabotage, virus, and terrorism), and includes:

(i) descriptions of roles and responsibilities: identifying key individuals and the recovery team responsible for implementing recovery actions; (ii) data backup plans, providing for periodic backups of data from database systems that can be used to reconstruct data; (iii) contingency plans and disaster recovery guides that will be followed by members of the recovery team before, during and after an unplanned disruptive event in order to minimize downtime and data loss; and (iv) procedures for annual testing and evaluating the BC/DR Plans including documenting the tests in writing.

10. Security Evaluations.

10.1 Klaay Affiliates perform periodic risk assessments that evaluate and assess the security of the system's physical configuration and environment, software, information handling processes, and user practices including appropriate logs and reports on security activity.

10.2 In addition, security policies are regularly reviewed and evaluated to ensure operational effectiveness, compliance with applicable laws and regulations, and to address new threats and risks.

10.3 Security Policies are also reviewed when there is a material change in Klaay’s business practices or the external threat environment that may reasonably implicate the security or integrity of records containing Personal Data. Klaay uses a documented change control process for software, systems, applications, and databases that ensures access changes are controlled, approved, and recorded.

10.4 Klaay will promptly notify Customer of any planned system configuration changes or other changes that would adversely affect the confidentiality, integrity, or availability of Customer Data.

10.5 Klaay will provide copies of available audit reports for the applicable Services to Customers upon written request and under NDA. Such audit reports, and the information they contain, are Klaay Confidential Information and must be handled by Customer accordingly. Such reports may be used solely by Customer to evaluate the design and operating effectiveness of defined controls applicable to the Services and are provided without any warranty. Klaay can also provide summary level penetration test documentation available to Customers upon request sanitized of any sensitive information.

11. Training and Secure Development Practices. The Klaay Information Security Policy is communicated to all Klaay personnel, employees, and contractors. Klaay provides periodic and mandatory security awareness training to employees and contractors (collectively “Personnel”). Klaay imposes disciplinary measures for violations of the Klaay Information Security Policy.

12. Subprocessors. Agreements with relevant subprocessors include requirements that these subprocessors address security risks, controls, and procedures for information systems and contain terms, conditions, and restrictions at least as protective and as restrictive as those set forth herein. Klaay shall supply each of its personnel and contractors with appropriate, ongoing training regarding information security procedures, risks, and threats and Klaay shall be responsible for the performance of any subcontractor. Klaay agrees that any Services performed for Customer involving use of Personal Data shall be performed only at the data center region and by personnel permitted under the Agreement.

13. Access and Review. Klaay will make summary level information regarding its security policies and procedures as well current, published, third-party audit reporting related to Customer’s Customer Data available for Customer’s review at Klaay upon reasonable prior written notice by Customer and subject to Klaay’s confidentiality and security conditions, and subject to a written and mutually agreed audit plan. Klaay reserves the right to require its prior approval to any third-party review of the DR Plan, and reasonably condition and restrict such third-party access. Customers may also review available audit reporting as outlined in Section 14. Klaay agrees that any Services performed for Customer involving use of Personal Data shall be performed only at the data center region and by personnel permitted under the Agreement.

14. Customer Audits. Klaay offers its Services in the cloud in a one-to-many business model that relies on standardization of best practices and industry standards for the benefit of its Customers and which is utilizing third-party providers and Sub-processors. As a result, onsite audits by Customers pose security and privacy risks to Klaay, other Klaay Customers and Klaay Sub-processors.

Moreover, some Sub-processors such as Heroku and Amazon Web Services (“AWS”) do not allow for physical audits of their data centers, but instead provide third party audits and certifications. It is for these reasons, among others, that Klaay’s security program consists of the audits, certifications and available documentation as part of balancing transparency regarding the security and privacy safeguards that Klaay has implemented, while also satisfying security and privacy requirements as part of security and privacy obligations to Klaay Customers, and its subprocessors, including AWS.

Therefore, Customer agrees to exercise its right to conduct an audit or inspection of Klaay’s processing of personal data within Customer Data by instructing Klaay to carry out audits using its current processes and timing. If Customer wishes to change this instruction regarding the audit or inspection, then Customer shall send such request by written notice to Klaay, and the parties agree to jointly discuss how to implement the changed instruction.

15. Hosting and Data Location. The Subscription Services and Customer Data are hosted on the Heroku platform, operated by Salesforce, Inc., in the United States (AWS us-east-1, Northern Virginia). Klaay will not move the hosting of Customer Data to another region without the express permission of Customer, as set out in Section 9.1 of the DPA.